Nextcloud / Contacts
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66554 | Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field | MEDIUM | 5.4 | Dec 5, 2025 |
| CVE-2023-33182 | Nextcloud Contacts photos only sanitized if mime type is all lower case | MEDIUM | 4.3 | May 30, 2023 |
| CVE-2021-39221 | XSS in Contacts | MEDIUM | 6.4 | Oct 25, 2021 |
| CVE-2020-8280 | A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks. | MEDIUM | 5.4 | Jan 6, 2021 |
| CVE-2020-8281 | A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks. | MEDIUM | 5.4 | Jan 6, 2021 |
| CVE-2020-8181 | A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars. | MEDIUM | 4.3 | Jul 10, 2020 |
| CVE-2018-3764 | In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. T… | MEDIUM | 4.8 | Jul 5, 2018 |
Showing 1 to 7 of 7 CVEs