# Files module - Security Update
We’ve recently addressed two security vulnerabilities (Self-XSS, Blind SQL Injection) in the CFiles module.
These issues were responsibly disclosed and are now fixed in **version 0.16.10**.\
You can find more details in the official advisory here:\
🔗 [GitHub Security Advisory GHSA-cw2v-c62w-5r43](https://github.com/humhub/cfiles/security/advisories/GHSA-cw2v-c62w-5r43)\
🔗 [GitHub Security Advisory GHSA-rfvq-g9rm-pgqj](https://github.com/humhub/cfiles/security/advisories/GHSA-rfvq-g9rm-pgqj)
**A big thank you to**\
_Researcher:_ Mike Cole\
_Organization:_ [Mantel Group](https://mantelgroup.com.au)
**Note:** All SaaS installations with Auto Update have already been patched.
We recommend all self-hosted instances update to the latest version as soon as possible.