Contacts
by Nextcloud
Source repositories
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8281 | Med | 0.35 | 5.4 | 0.01 | Jan 6, 2021 | A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks. | ||
| CVE-2020-8280 | Med | 0.35 | 5.4 | 0.01 | Jan 6, 2021 | A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks. | ||
| CVE-2018-3764 | Med | 0.31 | 4.8 | 0.01 | Jul 5, 2018 | In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged… | ||
| CVE-2020-8181 | Med | 0.28 | 4.3 | 0.01 | Jul 10, 2020 | A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars. | ||
| CVE-2025-66554 | Low | 0.00 | 3.5 | 0.00 | Dec 5, 2025 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were… | ||
| CVE-2023-33182 | Non | 0.00 | 0.0 | 0.01 | May 30, 2023 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to… | ||
| CVE-2021-39221 | Med | 0.00 | 6.4 | 0.01 | Oct 25, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file… |
- risk 0.35cvss 5.4epss 0.01
A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.
- risk 0.35cvss 5.4epss 0.01
A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.
- risk 0.31cvss 4.8epss 0.01
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged…
- risk 0.28cvss 4.3epss 0.01
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
- risk 0.00cvss 3.5epss 0.00
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were…
- risk 0.00cvss 0.0epss 0.01
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to…
- risk 0.00cvss 6.4epss 0.01
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file…