← Back

Nextcloud

nextcloud

372 CVEs • 39 products

Products (39)

Click to collapse
Toggle
Nextcloud
nextcloud
Desktop
desktop
Talk
talk
Deck
deck
Mail
mail
Calendar
calendar
User Oidc
user_oidc
Richdocuments
richdocuments
Tables
tables
Contacts
contacts
Circles
circles
Group Folders
group_folders
Approval
approval
Social
social
Server
server
Notes
notes
Guests
guests
Extract
extract
Lookup Server
lookup-server
Officeonline
officeonline
News
news
Nextcloud Mail
nextcloud_mail
Cookbook
cookbook
Zipper
zipper
Nextcloudpi
nextcloudpi
Flow
flow
Forms
forms

CVEs (372)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Nov 9, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Nov 2, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Nov 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Nov 2, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
1Nextcloud
1Deck
Jun 17, 2026
Oct 5, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
2Nextcloud
Opensuse
3Backports Sle
LeapPreferred Providers
Jun 17, 2026
Oct 5, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Oct 5, 2020
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
1Nextcloud
1Deck
Jun 17, 2026
Oct 5, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
1Nextcloud
1Desktop
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
1Nextcloud
1Desktop
Jun 17, 2026
Aug 21, 2020
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
1Nextcloud
1Desktop
Jun 17, 2026
Aug 21, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
1Nextcloud
1Desktop
Jun 17, 2026
Aug 17, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
1Nextcloud
1Desktop
Jun 17, 2026
Aug 10, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
1Nextcloud
1Desktop
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
1Nextcloud
1Preferred Providers
Jun 17, 2026
Jul 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
1Nextcloud
1Contacts
Jun 17, 2026
Jul 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
1Nextcloud
1Deck
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.1 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
1Nextcloud
1Talk
Jun 17, 2026
Jun 8, 2020
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
2Fedoraproject
Nextcloud
2Fedora
Mail
Jun 17, 2026
May 12, 2020
N/A· v4
7.0 HIGH· v3
6.8 MEDIUM· v2
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
May 12, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.