VYPR

Nextcloud

by Nextcloud

Source repositories

CVEs (144)

  • CVE-2019-15612MedFeb 4, 2020
    risk 0.38cvss 5.9epss 0.00

    A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

  • CVE-2018-16464MedOct 30, 2018
    risk 0.37cvss 5.7epss 0.01

    A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.

  • CVE-2026-45285MedJun 1, 2026
    risk 0.35cvss 6.4epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a…

  • CVE-2026-45275MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization…

  • CVE-2026-45267MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6.

  • CVE-2020-8294MedFeb 3, 2021
    risk 0.35cvss 5.4epss 0.01

    A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.

  • CVE-2020-8280MedJan 6, 2021
    risk 0.35cvss 5.4epss 0.01

    A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.

  • CVE-2020-8133MedNov 9, 2020
    risk 0.35cvss 5.3epss 0.01

    A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

  • CVE-2020-8189MedAug 21, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.

  • CVE-2020-8155MedMay 12, 2020
    risk 0.35cvss 5.4epss 0.01

    An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.

  • CVE-2019-15623MedFeb 4, 2020
    risk 0.35cvss 5.3epss 0.02

    Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

  • CVE-2019-15617MedFeb 4, 2020
    risk 0.35cvss 5.4epss 0.01

    A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

  • CVE-2019-15614MedFeb 4, 2020
    risk 0.35cvss 5.4epss 0.01

    Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.

  • CVE-2018-16467MedOct 30, 2018
    risk 0.35cvss 5.3epss 0.01

    A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.

  • CVE-2018-16465MedOct 30, 2018
    risk 0.35cvss 5.3epss 0.01

    Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.

  • CVE-2018-3781MedAug 13, 2018
    risk 0.35cvss 5.4epss 0.01

    A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

  • CVE-2016-9460MedMar 28, 2017
    risk 0.35cvss 5.3epss 0.02

    Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use…

  • CVE-2020-8118MedFeb 4, 2020
    risk 0.33cvss 5.0epss 0.01

    An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

  • CVE-2019-15624MedFeb 4, 2020
    risk 0.32cvss 4.9epss 0.01

    Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

  • CVE-2019-15611MedFeb 4, 2020
    risk 0.32cvss 4.9epss 0.01

    Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.

Page 3 of 8