Nextcloud
by Nextcloud
Source repositories
CVEs (144)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45545 | Hig | 0.46 | 8.2 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long… | ||
| CVE-2026-45156 | Hig | 0.46 | 8.1 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been… | ||
| CVE-2020-8156 | Hig | 0.46 | 7.0 | 0.01 | May 12, 2020 | A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. | ||
| CVE-2020-8236 | Med | 0.44 | 6.8 | 0.01 | Nov 2, 2020 | A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it. | ||
| CVE-2019-5455 | Med | 0.44 | 6.8 | 0.00 | Jul 30, 2019 | Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. | ||
| CVE-2019-5450 | Med | 0.44 | 6.8 | 0.01 | Jul 30, 2019 | Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML. | ||
| CVE-2025-59788 | Med | 0.42 | 6.4 | 0.00 | Dec 4, 2025 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute… | ||
| CVE-2021-39222 | Med | 0.42 | 6.4 | 0.01 | Nov 15, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the… | ||
| CVE-2021-32676 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2021 | Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk… | ||
| CVE-2021-22912 | Med | 0.42 | 6.5 | 0.01 | Jun 11, 2021 | Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user. | ||
| CVE-2021-22905 | Med | 0.42 | 6.5 | 0.01 | Jun 11, 2021 | Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by… | ||
| CVE-2020-8293 | Med | 0.42 | 6.5 | 0.02 | Jan 26, 2021 | A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules. | ||
| CVE-2020-8223 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2020 | A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves. | ||
| CVE-2020-8139 | Med | 0.42 | 6.5 | 0.02 | Mar 20, 2020 | A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. | ||
| CVE-2020-8138 | Med | 0.42 | 6.5 | 0.01 | Mar 20, 2020 | A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL. | ||
| CVE-2019-15621 | Med | 0.42 | 6.5 | 0.01 | Feb 4, 2020 | Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link. | ||
| CVE-2020-8120 | Med | 0.40 | 6.1 | 0.01 | Feb 4, 2020 | A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation. | ||
| CVE-2019-15615 | Med | 0.40 | 6.1 | 0.00 | Feb 4, 2020 | A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. | ||
| CVE-2019-5453 | Med | 0.40 | 6.1 | 0.00 | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | ||
| CVE-2026-45722 | Hig | 0.39 | 7.1 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a… |
- risk 0.46cvss 8.2epss 0.00
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long…
- risk 0.46cvss 8.1epss 0.00
Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been…
- risk 0.46cvss 7.0epss 0.01
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
- risk 0.44cvss 6.8epss 0.01
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
- risk 0.44cvss 6.8epss 0.00
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
- risk 0.44cvss 6.8epss 0.01
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
- risk 0.42cvss 6.4epss 0.00
Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute…
- risk 0.42cvss 6.4epss 0.01
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the…
- risk 0.42cvss 6.5epss 0.01
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk…
- risk 0.42cvss 6.5epss 0.01
Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.
- risk 0.42cvss 6.5epss 0.01
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by…
- risk 0.42cvss 6.5epss 0.02
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
- risk 0.42cvss 6.5epss 0.01
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
- risk 0.42cvss 6.5epss 0.02
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
- risk 0.42cvss 6.5epss 0.01
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
- risk 0.42cvss 6.5epss 0.01
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
- risk 0.40cvss 6.1epss 0.01
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
- risk 0.40cvss 6.1epss 0.00
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
- risk 0.40cvss 6.1epss 0.00
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
- risk 0.39cvss 7.1epss 0.00
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a…
Page 2 of 8