Nextcloud / Security-Advisories
260 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45810 | Nextcloud: Propfind requests for file comments allowed to load comments for other files | MEDIUM | 6.8 | Jun 1, 2026 |
| CVE-2026-45722 | Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views | HIGH | 7.1 | Jun 1, 2026 |
| CVE-2026-45691 | Nextcloud: Bypass of second factor authentication on DAV endpoints | MEDIUM | 5.9 | Jun 1, 2026 |
| CVE-2026-45690 | Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay | MEDIUM | 5.9 | Jun 1, 2026 |
| CVE-2026-45545 | Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution | HIGH | 8.2 | Jun 1, 2026 |
| CVE-2026-45544 | Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService | MEDIUM | 4.3 | Jun 1, 2026 |
| CVE-2026-45543 | Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share | MEDIUM | 5.3 | Jun 1, 2026 |
| CVE-2026-45286 | Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint | MEDIUM | 4.3 | Jun 1, 2026 |
| CVE-2026-45284 | Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate | HIGH | 8.8 | Jun 1, 2026 |
| CVE-2026-45285 | Nextcloud: Hidden Public Link creation when sharing to a Team External Member | MEDIUM | 6.4 | Jun 1, 2026 |
| CVE-2026-45283 | Nextcloud: Files Lock app allows users to lock and unlock files of other users | MEDIUM | 6.3 | Jun 1, 2026 |
| CVE-2026-45282 | Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-45281 | Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update | HIGH | 8.1 | Jun 1, 2026 |
| CVE-2026-45279 | Nextcloud: Limited path traversal via template API if using `{lang}` in config | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-45278 | Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass | MEDIUM | 6.1 | Jun 1, 2026 |
| CVE-2026-45277 | Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations | LOW | 3.3 | Jun 1, 2026 |
| CVE-2026-45275 | Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-45267 | Nextcloud: Missing permission check for from submissions | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-45266 | Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling | LOW | 3.5 | Jun 1, 2026 |
| CVE-2026-45159 | Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner | LOW | 3.5 | Jun 1, 2026 |
| CVE-2026-45157 | Nextcloud: Valid share tokens allow to access tempory upload files of share owner | MEDIUM | 6.3 | Jun 1, 2026 |
| CVE-2026-45156 | Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC | HIGH | 8.1 | Jun 1, 2026 |
| CVE-2026-45155 | Nextcloud: Private circle can be added to another circle via API | LOW | 2.6 | Jun 1, 2026 |
| CVE-2026-45154 | Nextcloud: Improper Access Control in Collectives | LOW | 2.6 | Jun 1, 2026 |
| CVE-2026-45153 | Nextcloud: PIN bypass in PassCodeActivity via back button | MEDIUM | 4.6 | Jun 1, 2026 |
Showing 1 to 25 of 260 CVEs