CVE-2025-9826: XSS
Published Sep 15, 2025
·Updated
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
Affected Software
2 affected components
M-Files Hubshare<25.8
M-Files Hubshare<25.8
Remediation
Information
Update to patched version 25.8 or newer.
Event History
Sep 15, 2025
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 24, 58011
Event
via FIRST·09:14 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9826?
CVE-2025-9826 is classified as a stored cross-site scripting vulnerability allowing authenticated attackers to execute scripts for other users.
2
How do I fix CVE-2025-9826?
To fix CVE-2025-9826, upgrade to M-Files Hubshare version 25.8 or later.
3
Who is affected by CVE-2025-9826?
CVE-2025-9826 affects users of M-Files Hubshare versions prior to 25.8.
4
What type of attack is possible with CVE-2025-9826?
CVE-2025-9826 allows authenticated attackers to perform stored cross-site scripting attacks.
5
Can I exploit CVE-2025-9826 without authentication?
No, CVE-2025-9826 requires authentication to exploit the stored cross-site scripting vulnerability.