Security-Advisories
Nextcloud · 260 CVEs
Nextcloud: Propfind requests for file comments allowed to load comments for other files
Jun 1, 2026
Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views
Jun 1, 2026
Nextcloud: Bypass of second factor authentication on DAV endpoints
Jun 1, 2026
Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay
Jun 1, 2026
Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution
Jun 1, 2026
Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService
Jun 1, 2026
Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share
Jun 1, 2026
Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint
Jun 1, 2026
Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Jun 1, 2026
Nextcloud: Hidden Public Link creation when sharing to a Team External Member
Jun 1, 2026
Nextcloud: Files Lock app allows users to lock and unlock files of other users
Jun 1, 2026
Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to…
Jun 1, 2026
Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update
Jun 1, 2026
Nextcloud: Limited path traversal via template API if using `{lang}` in config
Jun 1, 2026
Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass
Jun 1, 2026
Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations
Jun 1, 2026
Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers
Jun 1, 2026
Nextcloud: Missing permission check for from submissions
Jun 1, 2026
Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling
Jun 1, 2026
Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the shar…
Jun 1, 2026
Nextcloud: Valid share tokens allow to access tempory upload files of share owner
Jun 1, 2026
Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
Jun 1, 2026
Nextcloud: Private circle can be added to another circle via API
Jun 1, 2026
Nextcloud: Improper Access Control in Collectives
Jun 1, 2026
Nextcloud: PIN bypass in PassCodeActivity via back button
Jun 1, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-45810 | Nextcloud: Propfind requests for file comments allowed to load comments for other files | MEDIUM | 0.44% | Jun 1, 2026 |
| CVE-2026-45722 | Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views | HIGH | 0.49% | Jun 1, 2026 |
| CVE-2026-45691 | Nextcloud: Bypass of second factor authentication on DAV endpoints | MEDIUM | 0.43% | Jun 1, 2026 |
| CVE-2026-45690 | Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay | MEDIUM | 0.43% | Jun 1, 2026 |
| CVE-2026-45545 | Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution | HIGH | 0.52% | Jun 1, 2026 |
| CVE-2026-45544 | Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService | MEDIUM | 0.37% | Jun 1, 2026 |
| CVE-2026-45543 | Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share | MEDIUM | 0.46% | Jun 1, 2026 |
| CVE-2026-45286 | Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint | MEDIUM | 0.46% | Jun 1, 2026 |
| CVE-2026-45284 | Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate | HIGH | 0.36% | Jun 1, 2026 |
| CVE-2026-45285 | Nextcloud: Hidden Public Link creation when sharing to a Team External Member | MEDIUM | 0.49% | Jun 1, 2026 |
| CVE-2026-45283 | Nextcloud: Files Lock app allows users to lock and unlock files of other users | MEDIUM | 0.36% | Jun 1, 2026 |
| CVE-2026-45282 | Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access | MEDIUM | 0.48% | Jun 1, 2026 |
| CVE-2026-45281 | Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update | HIGH | 0.50% | Jun 1, 2026 |
| CVE-2026-45279 | Nextcloud: Limited path traversal via template API if using `{lang}` in config | MEDIUM | 0.57% | Jun 1, 2026 |
| CVE-2026-45278 | Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass | MEDIUM | 0.32% | Jun 1, 2026 |
| CVE-2026-45277 | Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations | LOW | 0.17% | Jun 1, 2026 |
| CVE-2026-45275 | Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers | MEDIUM | 0.49% | Jun 1, 2026 |
| CVE-2026-45267 | Nextcloud: Missing permission check for from submissions | MEDIUM | 0.51% | Jun 1, 2026 |
| CVE-2026-45266 | Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling | LOW | 0.35% | Jun 1, 2026 |
| CVE-2026-45159 | Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner | LOW | 0.35% | Jun 1, 2026 |
| CVE-2026-45157 | Nextcloud: Valid share tokens allow to access tempory upload files of share owner | MEDIUM | 0.39% | Jun 1, 2026 |
| CVE-2026-45156 | Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC | HIGH | 0.55% | Jun 1, 2026 |
| CVE-2026-45155 | Nextcloud: Private circle can be added to another circle via API | LOW | 0.31% | Jun 1, 2026 |
| CVE-2026-45154 | Nextcloud: Improper Access Control in Collectives | LOW | 0.31% | Jun 1, 2026 |
| CVE-2026-45153 | Nextcloud: PIN bypass in PassCodeActivity via back button | MEDIUM | 0.21% | Jun 1, 2026 |
Showing 1 to 25 of 260 CVEs