SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-18371

MEDIUM · CVSS 5.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An HTML injection vulnerability in M-Files Web prior to version 26.8.16330.2 allows authenticated attackers to manipulate the web user interface, potentially leading to unauthorized content display to other users. This could result in phishing attacks or misinformation being presented within the application. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-18371
Severity
MEDIUM
CVSS
5.1
EPSS
0.29%

Original NVD Description

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.