CVE-2025-13008None▾ SunlitAn information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-43452Medium· 4.6This issue was addressed by restricting options offered on a locked device
CVE-2025-43439Medium· 5.5A privacy issue was addressed by removing sensitive data
CVE-2025-43399High· 7.5This issue was addressed with improved redaction of sensitive information
CVE-2025-43389Medium· 5.5A privacy issue was addressed by removing the vulnerable code
CVE-2026-39372Medium· 4.9InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
CVE-2025-10450High· 7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic