← Back

Nextcloud

nextcloud

372 CVEs • 39 products

Products (39)

Click to collapse
Toggle
Nextcloud
nextcloud
Desktop
desktop
Talk
talk
Deck
deck
Mail
mail
Calendar
calendar
User Oidc
user_oidc
Richdocuments
richdocuments
Tables
tables
Contacts
contacts
Circles
circles
Group Folders
group_folders
Approval
approval
Social
social
Server
server
Notes
notes
Guests
guests
Extract
extract
Lookup Server
lookup-server
Officeonline
officeonline
News
news
Nextcloud Mail
nextcloud_mail
Cookbook
cookbook
Zipper
zipper
Nextcloudpi
nextcloudpi
Flow
flow
Forms
forms

CVEs (372)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nextcloud
1Nextcloud Server
Jun 17, 2026
May 12, 2020
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
2Fedoraproject
Nextcloud
2Fedora
Group Folders
Jun 17, 2026
May 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
1Nextcloud
1Desktop
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
3Nextcloud
NovellOpensuse
3Backports Sle
Nextcloud ServerSuse Linux Enterprise Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
3Nextcloud
OpensuseSuse
3Backports
Nextcloud ServerSuse Linux Enterprise Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
3Nextcloud
OpensuseSuse
3Backports Sle
Nextcloud ServerPackage Hub
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
1Nextcloud
1Nextcloud
Jun 17, 2026
Feb 4, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
1Nextcloud
1Talk
Jun 17, 2026
Feb 4, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
1Nextcloud
3Deck
Nextcloud ServerTalk
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.