VYPR

Nextcloud

by Nextcloud

Source repositories

CVEs (144)

  • CVE-2021-22879HigApr 14, 2021
    risk 0.00cvss 8.8epss 0.05

    Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

  • CVE-2021-22878MedMar 3, 2021
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

  • CVE-2021-22877MedMar 3, 2021
    risk 0.00cvss 6.5epss 0.02

    A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.

  • CVE-2020-8296MedMar 3, 2021
    risk 0.00cvss 6.7epss 0.01

    Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

Page 8 of 8