Nextcloud / Richdocuments
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-28645 | Secure view can be bypassed by using internal API endpoint in Nextcloud richdocuments | MEDIUM | 6.5 | Mar 31, 2023 |
| CVE-2023-25159 | Nextcloud Server previews are accessible without a watermark | MEDIUM | 5.3 | Feb 13, 2023 |
| CVE-2023-25150 | Document content of files can be obtained through Collabora for files of other users | MEDIUM | 5.8 | Feb 8, 2023 |
| CVE-2022-31024 | Federated editing allows iframing remote servers by default in richdocuments | MEDIUM | 6.5 | Jun 2, 2022 |
| CVE-2021-39223 | File path disclosure of shared files in Richdocuments application | MEDIUM | 5.3 | Oct 25, 2021 |
| CVE-2021-37629 | Lack of ratelimit on Richdocuments OCS endpoint in nextcloud | MEDIUM | 5.3 | Sep 7, 2021 |
| CVE-2021-37628 | File Drop can be bypassed using Richdocuments app in nextcloud | HIGH | 7.5 | Sep 7, 2021 |
| CVE-2021-32748 | WOPI API not protected by credentials/IP check | MEDIUM | 4.3 | Jul 27, 2021 |
Showing 1 to 8 of 8 CVEs