VYPR
Medium severity4.8NVD Advisory· Published Feb 4, 2020· Updated Jun 17, 2026

CVE-2019-15618

CVE-2019-15618

Description

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*
    Range: <14.0.9
  • Nextcloud/Nextcloudllm-fuzzy2 versions
    = 15.0.5+ 1 more
    • (no CPE)range: = 15.0.5
    • (no CPE)range: 15.0.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.