CVE-2025-11681
Severity CVSS v4.0:
HIGH
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
17/11/2025
Last modified:
20/11/2025
Description
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* | 25.2.14524.13 (excluding) | |
| cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:* | 25.11.15392.1 (excluding) | |
| cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* | 25.8.15085.13 (including) | 25.8.15085.17 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



