CVE-2025-14267
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-212
- Published
- 2025-12-19
- Last modified
- 2026-03-12
Affected products
- M-Files Corporation M-Files Server
Weakness type
Related vulnerabilities
- CVE-2026-86740 — Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
- CVE-2026-82069 — Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-78658 — IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
- CVE-2026-85094 — The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin...
- CVE-2026-62900 — .NET Information Disclosure Vulnerability
- CVE-2024-5300 — AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
- CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes