VYPR

Nextcloud

by Nextcloud

Source repositories

CVEs (144)

  • CVE-2018-16463LowOct 30, 2018
    risk 0.20cvss 3.1epss 0.01

    A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

  • CVE-2019-15620LowFeb 4, 2020
    risk 0.18cvss 2.7epss 0.01

    Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.

  • CVE-2026-45266LowJun 1, 2026
    risk 0.16cvss 3.5epss 0.00

    Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions…

  • CVE-2026-45159LowJun 1, 2026
    risk 0.16cvss 3.5epss 0.00

    Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files…

  • CVE-2019-15622LowFeb 4, 2020
    risk 0.16cvss 2.4epss 0.01

    Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

  • CVE-2019-5452LowJul 30, 2019
    risk 0.16cvss 2.4epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.

  • CVE-2026-45278LowJun 1, 2026
    risk 0.14cvss 3.3epss 0.00

    Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in…

  • CVE-2020-8173LowNov 2, 2020
    risk 0.14cvss 2.2epss 0.00

    A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.

  • CVE-2025-66558LowDec 5, 2025
    risk 0.00cvss 3.1epss 0.00

    Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols.…

  • CVE-2025-66557MedDec 5, 2025
    risk 0.00cvss 5.4epss 0.00

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other…

  • CVE-2025-66556LowDec 5, 2025
    risk 0.00cvss 3.5epss 0.00

    Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and…

  • CVE-2025-66548LowDec 5, 2025
    risk 0.00cvss 3.3epss 0.00

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a…

  • CVE-2024-52509LowNov 15, 2024
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from…

  • CVE-2024-37314LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.

  • CVE-2024-22404MedJan 18, 2024
    risk 0.00cvss 4.1epss 0.01

    Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0.…

  • CVE-2023-49790MedDec 22, 2023
    risk 0.00cvss 4.3epss 0.00

    The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch.…

  • CVE-2023-48307LowNov 21, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0…

  • CVE-2023-45149MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is…

  • CVE-2023-45660MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded…

  • CVE-2023-39962HigAug 10, 2023
    risk 0.00cvss 7.7epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or…

Page 5 of 8