Nextcloud / Deck
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77170 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has p… | MEDIUM | 4.3 | Sep 18, 2026 |
| CVE-2025-66557 | Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners | MEDIUM | 5.4 | Dec 5, 2025 |
| CVE-2025-66548 | Nextcloud Deck app allows to spoof file extensions by using RTLO characters | MEDIUM | 5.5 | Dec 5, 2025 |
| CVE-2024-37883 | Nextcloud Deck can access comments and attachments of deleted cards | MEDIUM | 4.3 | Jun 14, 2024 |
| CVE-2024-22213 | Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app | MEDIUM | 5.4 | Jan 18, 2024 |
| CVE-2023-22471 | Nextcloud Deck vulnerable to authorization bypass | MEDIUM | 4.3 | Jan 14, 2023 |
| CVE-2023-22470 | Nextcloud Deck vulnerable to uncontrolled resource consumption | MEDIUM | 6.5 | Jan 14, 2023 |
| CVE-2023-22469 | Nextcloud Deck card vulnerable to data leak to unauthorized users via reference preview cache | MEDIUM | 5.8 | Jan 10, 2023 |
| CVE-2022-24906 | Error in deleting deck cards attachment reveals the full application path in Nextcloud Deck | MEDIUM | 4.3 | May 20, 2022 |
| CVE-2022-29159 | Possibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud Deck | MEDIUM | 5.0 | May 20, 2022 |
| CVE-2021-39225 | Missing permission check on Deck API | HIGH | 8.1 | Oct 25, 2021 |
| CVE-2021-37631 | Circle can be accessed by non-Circle members in Nextcloud Deck | MEDIUM | 6.5 | Sep 7, 2021 |
| CVE-2021-22913 | Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead… | MEDIUM | 6.5 | Jun 11, 2021 |
| CVE-2020-8297 | Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access… | MEDIUM | 4.3 | Feb 23, 2021 |
| CVE-2020-8182 | Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. | HIGH | 8.0 | Oct 5, 2020 |
| CVE-2020-8235 | Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments. | MEDIUM | 4.3 | Oct 5, 2020 |
| CVE-2020-8179 | Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. | MEDIUM | 4.1 | Jul 2, 2020 |
| CVE-2019-15619 | Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an X… | MEDIUM | 4.8 | Feb 4, 2020 |
Showing 1 to 17 of 17 CVEs