Nextcloud / Calendar
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45286 | Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint | MEDIUM | 4.3 | Jun 1, 2026 |
| CVE-2025-66550 | Nextcloud Calendar attachments of local files are offered to downloaded | MEDIUM | 5.7 | Dec 5, 2025 |
| CVE-2025-66546 | Nextcloud Calendar app allowed booking appointments without the generated token | LOW | 3.3 | Dec 5, 2025 |
| CVE-2025-66511 | Nextcloud Calendar app used predictable proposal participant tokens | MEDIUM | 6.5 | Dec 5, 2025 |
| CVE-2024-37316 | Nextcloud Calendar's event create can create attachments that link to other websites | MEDIUM | 4.6 | Jun 14, 2024 |
| CVE-2023-48308 | Calendar app returns full stacktrace when an error happens while editing appointment | MEDIUM | 6.5 | Dec 21, 2023 |
| CVE-2023-45150 | Inviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsive | MEDIUM | 4.3 | Oct 16, 2023 |
| CVE-2023-33183 | Error in calendar when booking an appointment reveals the full path of the website | MEDIUM | 4.3 | May 30, 2023 |
| CVE-2022-24838 | Command Injection in Appointment Emails for Nextcloud Calendar | CRITICAL | 9.8 | Apr 11, 2022 |
| CVE-2018-3763 | In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-inte… | MEDIUM | 4.8 | Jul 5, 2018 |
Showing 1 to 10 of 10 CVEs