Back to Database
Status published
High
CVE-2024-6881
Stored XSS Vulnerability
Vulnerability Description
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6881
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Markus Tirrenberg / WithSecure
- Emma Kantanen / WithSecure
References
More from M-Files Corporation
View All →CVE-2025-9826
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8...
High
7
CVE-2025-5964
Path traversal in M-Files API
High
8.4
CVE-2025-3087
Stored XSS Vulnerability in M-Files Web
Medium
5.1
CVE-2025-3086
User in anonymous role could create and delete views
Medium
6.3
CVE-2025-2159
Stored XSS in M-Files Admin user interface
Medium
5.1
Affected Vendor
M-Files Corporation
View all reports →Affected Software
Hubshare
Vulnerable Versions:
0
Timeline
Official Publish:
July 29th, 2024
Last Modified:
February 23rd, 2026
Added to House:
July 22nd, 2026