← Back

Nextcloud

nextcloud

365 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Nextcloud
nextcloud
Desktop
desktop
Talk
talk
Deck
deck
Mail
mail
Calendar
calendar
User Oidc
user_oidc
Richdocuments
richdocuments
Contacts
contacts
Tables
tables
Circles
circles
Group Folders
group_folders
Approval
approval
Social
social
Server
server
Notes
notes
Guests
guests
Extract
extract
Lookup Server
lookup-server
Officeonline
officeonline
News
news
Nextcloud Mail
nextcloud_mail
Cookbook
cookbook
Zipper
zipper
Nextcloudpi
nextcloudpi
Flow
flow

CVEs (365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
3Nextcloud
NovellOpensuse
3Backports Sle
Nextcloud ServerSuse Linux Enterprise Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
3Nextcloud
OpensuseSuse
3Backports
Nextcloud ServerSuse Linux Enterprise Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
3Nextcloud
OpensuseSuse
3Backports Sle
Nextcloud ServerPackage Hub
Nov 21, 2024
Feb 4, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
1Nextcloud
1Nextcloud
Nov 21, 2024
Feb 4, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
1Nextcloud
1Talk
Nov 21, 2024
Feb 4, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
1Nextcloud
3Deck
Nextcloud ServerTalk
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
1Nextcloud
1Nextcloud
Nov 21, 2024
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
1Nextcloud
1Nextcloud
Nov 21, 2024
Feb 4, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
2Nextcloud
Opensuse
2Backports
Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 4, 2020
N/A· v4
5.9 MEDIUM· v3
3.2 LOW· v2
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
1Nextcloud
1Nextcloud
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
1Nextcloud
1Circles
Nov 21, 2024
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
1Nextcloud
1Lookup Server
Nov 21, 2024
Aug 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.