VYPR

Nextcloud

by Nextcloud

Source repositories

CVEs (144)

  • CVE-2026-45545HigJun 1, 2026
    risk 0.46cvss 8.2epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long…

  • CVE-2026-45156HigJun 1, 2026
    risk 0.46cvss 8.1epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been…

  • CVE-2020-8156HigMay 12, 2020
    risk 0.46cvss 7.0epss 0.01

    A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.

  • CVE-2020-8236MedNov 2, 2020
    risk 0.44cvss 6.8epss 0.01

    A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

  • CVE-2019-5455MedJul 30, 2019
    risk 0.44cvss 6.8epss 0.00

    Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.

  • CVE-2019-5450MedJul 30, 2019
    risk 0.44cvss 6.8epss 0.01

    Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.

  • CVE-2025-59788MedDec 4, 2025
    risk 0.42cvss 6.4epss 0.00

    Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute…

  • CVE-2021-39222MedNov 15, 2021
    risk 0.42cvss 6.4epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the…

  • CVE-2021-32676MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk…

  • CVE-2021-22912MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.01

    Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.

  • CVE-2021-22905MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.01

    Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by…

  • CVE-2020-8293MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.02

    A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.

  • CVE-2020-8223MedOct 5, 2020
    risk 0.42cvss 6.5epss 0.01

    A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

  • CVE-2020-8139MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.02

    A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

  • CVE-2020-8138MedMar 20, 2020
    risk 0.42cvss 6.5epss 0.01

    A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

  • CVE-2019-15621MedFeb 4, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

  • CVE-2020-8120MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.01

    A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

  • CVE-2019-15615MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.00

    A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.

  • CVE-2019-5453MedJul 30, 2019
    risk 0.40cvss 6.1epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.

  • CVE-2026-45722HigJun 1, 2026
    risk 0.39cvss 7.1epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a…

Page 2 of 8