Nextcloud / Mail
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66514 | Nextcloud Mail stored HTML injection in subject text | MEDIUM | 5.4 | Dec 5, 2025 |
| CVE-2024-52509 | Nextcloud Mail app does not respect download permissions in shares | MEDIUM | 5.7 | Nov 15, 2024 |
| CVE-2024-52508 | Nextcloud Mail auto configurator can be tricked into sending account information to wrong servers | HIGH | 8.2 | Nov 15, 2024 |
| CVE-2023-48307 | Nextcloud Mail app vulnerable to Server-Side Request Forgery | CRITICAL | 9.8 | Nov 21, 2023 |
| CVE-2023-45660 | Require strict cookies for image proxy requests in Nextcloud Mail | MEDIUM | 4.3 | Oct 16, 2023 |
| CVE-2023-33184 | Blind SSRF in the Nextcloud Mail app on avatar endpoint | MEDIUM | 5.3 | May 27, 2023 |
| CVE-2023-25160 | IDOR Vulnerability in Nextcloud Mail | MEDIUM | 5.3 | Feb 13, 2023 |
| CVE-2023-23943 | Blind SSRF via server URL input in the Nextcloud Mail app | MEDIUM | 5.0 | Feb 6, 2023 |
| CVE-2023-23944 | Nexcloud Mail app temporarily stores cleartext password in database | MEDIUM | 6.5 | Feb 6, 2023 |
| CVE-2022-31119 | Password disclosure in log file in Nextcloud Mail App | MEDIUM | 4.9 | Aug 4, 2022 |
| CVE-2022-31132 | Unauthenticated SSRF in 3rd party module "cerdic/csstidy" | CRITICAL | 9.8 | Aug 4, 2022 |
| CVE-2021-39220 | Bypass of image blocking in Nextcloud Mail | LOW | 3.5 | Oct 25, 2021 |
| CVE-2021-32707 | Bypass of image blocking in Nextcloud Mail | MEDIUM | 4.3 | Jul 12, 2021 |
| CVE-2021-32652 | Missing permission check on email metadata retrieval | HIGH | 8.8 | Jun 1, 2021 |
| CVE-2020-8156 | A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. | HIGH | 7.0 | May 12, 2020 |
Showing 1 to 15 of 15 CVEs