CSS Injection Vulnerability in M-Files Web by M-Files Corporation
CVE-2026-18372
4.8MEDIUM
What is CVE-2026-18372?
A CSS injection vulnerability has been identified in M-Files Web prior to version 26.8.16330.2, allowing authenticated vault administrators to inject arbitrary CSS. This exploitation can affect the web user interface viewed by other vault users, potentially leading to a range of security implications including manipulation of the UI and user data exposure.
Affected Version(s)
M-Files Web 0 < 26.8.16330.2
