Security-Advisories

Nextcloud · 260 CVEs

CVE-2026-45810
MEDIUM

Nextcloud: Propfind requests for file comments allowed to load comments for other files

Jun 1, 2026

CVE-2026-45722
HIGH

Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views

Jun 1, 2026

CVE-2026-45691
MEDIUM

Nextcloud: Bypass of second factor authentication on DAV endpoints

Jun 1, 2026

CVE-2026-45690
MEDIUM

Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay

Jun 1, 2026

CVE-2026-45545
HIGH

Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution

Jun 1, 2026

CVE-2026-45544
MEDIUM

Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService

Jun 1, 2026

CVE-2026-45543
MEDIUM

Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share

Jun 1, 2026

CVE-2026-45286
MEDIUM

Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint

Jun 1, 2026

CVE-2026-45284
HIGH

Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate

Jun 1, 2026

CVE-2026-45285
MEDIUM

Nextcloud: Hidden Public Link creation when sharing to a Team External Member

Jun 1, 2026

CVE-2026-45283
MEDIUM

Nextcloud: Files Lock app allows users to lock and unlock files of other users

Jun 1, 2026

CVE-2026-45282
MEDIUM

Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to…

Jun 1, 2026

CVE-2026-45281
HIGH

Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update

Jun 1, 2026

CVE-2026-45279
MEDIUM

Nextcloud: Limited path traversal via template API if using `{lang}` in config

Jun 1, 2026

CVE-2026-45278
MEDIUM

Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass

Jun 1, 2026

CVE-2026-45277
LOW

Nextcloud: Information disclosure in Nextcloud Approval app via fileId parameter reveals workflow associations

Jun 1, 2026

CVE-2026-45275
MEDIUM

Nextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approvers

Jun 1, 2026

CVE-2026-45267
MEDIUM

Nextcloud: Missing permission check for from submissions

Jun 1, 2026

CVE-2026-45266
LOW

Nextcloud: Unauthorized force-mute from missing permission check when using internal signaling

Jun 1, 2026

CVE-2026-45159
LOW

Nextcloud: Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the shar…

Jun 1, 2026

CVE-2026-45157
MEDIUM

Nextcloud: Valid share tokens allow to access tempory upload files of share owner

Jun 1, 2026

CVE-2026-45156
HIGH

Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC

Jun 1, 2026

CVE-2026-45155
LOW

Nextcloud: Private circle can be added to another circle via API

Jun 1, 2026

CVE-2026-45154
LOW

Nextcloud: Improper Access Control in Collectives

Jun 1, 2026

CVE-2026-45153
MEDIUM

Nextcloud: PIN bypass in PassCodeActivity via back button

Jun 1, 2026

Showing 1 to 25 of 260 CVEs