Nextcloud
by Nextcloud
Source repositories
CVEs (144)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15612 | Med | 0.38 | 5.9 | 0.00 | Feb 4, 2020 | A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. | ||
| CVE-2018-16464 | Med | 0.37 | 5.7 | 0.01 | Oct 30, 2018 | A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password. | ||
| CVE-2026-45285 | Med | 0.35 | 6.4 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a… | ||
| CVE-2026-45275 | Med | 0.35 | 6.5 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization… | ||
| CVE-2026-45267 | Med | 0.35 | 6.5 | 0.00 | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6. | ||
| CVE-2020-8294 | Med | 0.35 | 5.4 | 0.01 | Feb 3, 2021 | A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format. | ||
| CVE-2020-8280 | Med | 0.35 | 5.4 | 0.01 | Jan 6, 2021 | A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks. | ||
| CVE-2020-8133 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2020 | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file. | ||
| CVE-2020-8189 | Med | 0.35 | 5.4 | 0.01 | Aug 21, 2020 | A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt. | ||
| CVE-2020-8155 | Med | 0.35 | 5.4 | 0.01 | May 12, 2020 | An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF. | ||
| CVE-2019-15623 | Med | 0.35 | 5.3 | 0.02 | Feb 4, 2020 | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. | ||
| CVE-2019-15617 | Med | 0.35 | 5.4 | 0.01 | Feb 4, 2020 | A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. | ||
| CVE-2019-15614 | Med | 0.35 | 5.4 | 0.01 | Feb 4, 2020 | Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. | ||
| CVE-2018-16467 | Med | 0.35 | 5.3 | 0.01 | Oct 30, 2018 | A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. | ||
| CVE-2018-16465 | Med | 0.35 | 5.3 | 0.01 | Oct 30, 2018 | Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load. | ||
| CVE-2018-3781 | Med | 0.35 | 5.4 | 0.01 | Aug 13, 2018 | A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. | ||
| CVE-2016-9460 | Med | 0.35 | 5.3 | 0.02 | Mar 28, 2017 | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use… | ||
| CVE-2020-8118 | Med | 0.33 | 5.0 | 0.01 | Feb 4, 2020 | An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application. | ||
| CVE-2019-15624 | Med | 0.32 | 4.9 | 0.01 | Feb 4, 2020 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. | ||
| CVE-2019-15611 | Med | 0.32 | 4.9 | 0.01 | Feb 4, 2020 | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications. |
- risk 0.38cvss 5.9epss 0.00
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
- risk 0.37cvss 5.7epss 0.01
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
- risk 0.35cvss 6.4epss 0.00
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a…
- risk 0.35cvss 6.5epss 0.00
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization…
- risk 0.35cvss 6.5epss 0.00
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6.
- risk 0.35cvss 5.4epss 0.01
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
- risk 0.35cvss 5.4epss 0.01
A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.
- risk 0.35cvss 5.3epss 0.01
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- risk 0.35cvss 5.4epss 0.01
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
- risk 0.35cvss 5.4epss 0.01
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
- risk 0.35cvss 5.3epss 0.02
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
- risk 0.35cvss 5.4epss 0.01
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
- risk 0.35cvss 5.4epss 0.01
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
- risk 0.35cvss 5.3epss 0.01
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
- risk 0.35cvss 5.3epss 0.01
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
- risk 0.35cvss 5.4epss 0.01
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
- risk 0.35cvss 5.3epss 0.02
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use…
- risk 0.33cvss 5.0epss 0.01
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
- risk 0.32cvss 4.9epss 0.01
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
- risk 0.32cvss 4.9epss 0.01
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
Page 3 of 8