CVE-2026-18371: M-Files Corporation M-Files Web
Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.
HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.
Affected products
- M-Files Corporation M-Files Web: before 26.8.16330.2 (fixed in 26.8.16330.2)
Published 2026-08-19. Last modified 2026-08-31.