Low severity3.5NVD Advisory· Published Dec 5, 2025· Updated Jun 17, 2026
CVE-2025-66545
CVE-2025-66545
Description
Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*range: <14.0.11
- (no CPE)range: <14.0.11, <15.3.12, <16.0.15, <17.0.14, <18.1.8, <19.1.8, <20.1.2
- Range: < 14.0.11
Patches
Vulnerability mechanics
References
4- github.com/nextcloud/groupfolders/commit/bbe87ebed8da23e9df4db637a76fbc8d36439d58nvdPatch
- github.com/nextcloud/groupfolders/pull/4076nvdIssue TrackingPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-2vrq-fhmf-c49mnvdPatchVendor Advisory
- github.com/nextcloud/groupfolders/issues/4041nvdIssue Tracking
News mentions
0No linked articles in our index yet.