Nextcloud / Nextcloud Server
189 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45810 | Nextcloud: Propfind requests for file comments allowed to load comments for other files | MEDIUM | 6.8 | Jun 1, 2026 |
| CVE-2026-45691 | Nextcloud: Bypass of second factor authentication on DAV endpoints | MEDIUM | 5.9 | Jun 1, 2026 |
| CVE-2026-45690 | Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay | MEDIUM | 5.9 | Jun 1, 2026 |
| CVE-2026-45285 | Nextcloud: Hidden Public Link creation when sharing to a Team External Member | MEDIUM | 6.4 | Jun 1, 2026 |
| CVE-2026-45283 | Nextcloud: Files Lock app allows users to lock and unlock files of other users | MEDIUM | 6.3 | Jun 1, 2026 |
| CVE-2026-45282 | Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-45281 | Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update | HIGH | 8.1 | Jun 1, 2026 |
| CVE-2026-45279 | Nextcloud: Limited path traversal via template API if using `{lang}` in config | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2025-64011 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews o… | MEDIUM | 4.3 | Dec 12, 2025 |
| CVE-2025-66552 | Nextcloud Server admin_audit does not log all actions on files in groupfolders | MEDIUM | 4.3 | Dec 5, 2025 |
| CVE-2025-66547 | Nextcloud Server users can modify tags on files that do not belong to them | MEDIUM | 4.3 | Dec 5, 2025 |
| CVE-2025-66512 | Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud | MEDIUM | 6.1 | Dec 5, 2025 |
| CVE-2025-66510 | Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list | MEDIUM | 4.9 | Dec 5, 2025 |
| CVE-2025-59788 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28,… | MEDIUM | 6.4 | Dec 4, 2025 |
| CVE-2025-47794 | Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permission | MEDIUM | 4.3 | May 16, 2025 |
| CVE-2025-47793 | Nextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attachment in text file | MEDIUM | 6.5 | May 16, 2025 |
| CVE-2025-47791 | Nextcloud Server's test remote endpoint is not rate limited | MEDIUM | 5.3 | May 16, 2025 |
| CVE-2025-47790 | Nextcloud Server doesn't request second factor after session timeout | MEDIUM | 6.4 | May 16, 2025 |
| CVE-2024-52513 | Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares | MEDIUM | 4.3 | Nov 15, 2024 |
| CVE-2024-52514 | Nextcloud Server allows users to copy folder that contain files that are blocked by the files access control | MEDIUM | 4.1 | Nov 15, 2024 |
| CVE-2024-52515 | Nextcloud Server has incomplete sanitization of SVG files allows to embed other images into previews | MEDIUM | 6.5 | Nov 15, 2024 |
| CVE-2024-52516 | Nextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of them | MEDIUM | 4.3 | Nov 15, 2024 |
| CVE-2024-52517 | Nextcloud Server's global credentials of external storages are sent back to the frontend | MEDIUM | 5.9 | Nov 15, 2024 |
| CVE-2024-52518 | Nextcloud Server is missing password confirmation when changing external storage options | MEDIUM | 5.4 | Nov 15, 2024 |
| CVE-2024-52519 | Nextcloud Server's OAuth2 client secrets were stored in a recoverable way | HIGH | 8.2 | Nov 15, 2024 |
Showing 1 to 25 of 189 CVEs