Description
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 25.8
Credits
Kristian von Strokirch / Certezza AB 
References
product.m-files.com/security-advisories/cve-2025-9826/