CVEs (116)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malic...Show more |
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters. |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable i...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker cou...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud ser...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of i...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only re...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action...Show more |
2Nextcloud Owncloud2Nextcloud OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could cra...Show more |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log i...Show more |
ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file. |
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via u...Show more |
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows re...Show more |
ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct request. |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 6, 2026 Sep 17, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML...Show more |
1Owncloud 2Owncloud Owncloud ServerMay 6, 2026 Jan 8, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages. |
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote a...Show more |
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption)...Show more |
1Owncloud 2Owncloud Owncloud ServerMay 6, 2026 Jan 8, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitra...Show more |