Nextcloud / Talk
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66556 | Nextcloud talk allows participants to blindly delete poll drafts of other users by ID | MEDIUM | 4.3 | Dec 5, 2025 |
| CVE-2023-45149 | Password of talk conversations can be bruteforced in Nextcloud | MEDIUM | 4.3 | Oct 16, 2023 |
| CVE-2023-39957 | Path traversal allows tricking the Talk Android app into writing files into it's root directory | HIGH | 7.8 | Aug 10, 2023 |
| CVE-2023-30540 | Chat poll data can still be queried from API after purging history in Nextcloud talk | MEDIUM | 4.3 | Apr 17, 2023 |
| CVE-2023-28845 | Chat room membership disclosed via autocompletion in Nextcloud talk | LOW | 3.5 | Mar 31, 2023 |
| CVE-2023-22473 | Passcode bypass on Talk-Android app | LOW | 2.1 | Jan 9, 2023 |
| CVE-2022-41926 | Nextcloud Talk Android broadcast incorrect permission handling | MEDIUM | 5.5 | Nov 25, 2022 |
| CVE-2022-39212 | Last video frame is still sent after video is disabled in a call in Nextcloud Talk | MEDIUM | 5.3 | Sep 16, 2022 |
| CVE-2022-35932 | Missing rate limit when trying to join a password protected Nextcloud Talk conversation | MEDIUM | 5.3 | Aug 12, 2022 |
| CVE-2022-24890 | Exposure of Private Personal Information to an Unauthorized Actor in Nextcloud Talk | MEDIUM | 4.3 | May 17, 2022 |
| CVE-2022-24887 | Open Redirect in Nextcloud Talk | MEDIUM | 6.1 | Apr 27, 2022 |
| CVE-2021-41181 | Nextcloud Talk app exposes chat messages on lockscreen | LOW | 2.4 | Mar 8, 2022 |
| CVE-2021-41180 | Geolocation preview links can be set to arbitrary links in nextcloud talk | MEDIUM | 6.1 | Mar 8, 2022 |
| CVE-2021-39222 | XSS in Talk | MEDIUM | 6.4 | Nov 15, 2021 |
| CVE-2021-32689 | Nextcloud Talk not properly disassociating users from chats after account deletion | HIGH | 8.1 | Jul 12, 2021 |
| CVE-2021-32676 | Session Fixation in Nextcloud Talk | MEDIUM | 6.5 | Jun 16, 2021 |
| CVE-2020-8180 | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator. | CRITICAL | 9.9 | Jun 8, 2020 |
| CVE-2019-15620 | Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the proje… | LOW | 2.7 | Feb 4, 2020 |
| CVE-2019-15619 | Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an X… | MEDIUM | 4.8 | Feb 4, 2020 |
| CVE-2018-3781 | A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing… | MEDIUM | 5.4 | Aug 13, 2018 |
Showing 1 to 20 of 20 CVEs