Nextcloud
by Nextcloud
Source repositories
CVEs (144)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22879 | Hig | 0.00 | 8.8 | 0.05 | Apr 14, 2021 | Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation. | ||
| CVE-2021-22878 | Med | 0.00 | 4.8 | 0.01 | Mar 3, 2021 | Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. | ||
| CVE-2021-22877 | Med | 0.00 | 6.5 | 0.02 | Mar 3, 2021 | A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. | ||
| CVE-2020-8296 | Med | 0.00 | 6.7 | 0.01 | Mar 3, 2021 | Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. |
- risk 0.00cvss 8.8epss 0.05
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
- risk 0.00cvss 4.8epss 0.01
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
- risk 0.00cvss 6.5epss 0.02
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
- risk 0.00cvss 6.7epss 0.01
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
Page 8 of 8