Vulnerabilities in Nextcloud

297 results
Vexday analysis

Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.

CVE-2023-25579MEDIUMDirectory traversal in Nextcloud serverEPSS 0.5%CVE-2024-22213NONECross-site Scripting when sending HTML as a comment in the Nextcloud Deck appEPSS 0.5%CVE-2026-45281HIGHNextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set UpdateEPSS 0.5%CVE-2024-52519LOWNextcloud Server's OAuth2 client secrets were stored in a recoverable wayEPSS 0.5%CVE-2022-39364MEDIUMException logging in Sharepoint app reveals clear-text connection detailsEPSS 0.5%CVE-2023-35173MEDIUMEnd-to-End encrypted file-drops can be made inaccessibleEPSS 0.5%CVE-2026-45722HIGHNextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table ViewsEPSS 0.5%CVE-2022-41882MEDIUMNextcloud Desktop vulnerable to code injection via malicious linkEPSS 0.5%CVE-2026-45275MEDIUMNextcloud: Authorization bypass in approval feature allows unauthorized file sharing with approversEPSS 0.5%CVE-2026-45285MEDIUMNextcloud: Hidden Public Link creation when sharing to a Team External MemberEPSS 0.5%CVE-2026-45282MEDIUMNextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file accessEPSS 0.5%CVE-2024-52514MEDIUMNextcloud Server allows users to copy folder that contain files that are blocked by the files access controlEPSS 0.5%CVE-2023-45151MEDIUMOAuth2 client_secret stored in plain text in the Nextcloud databaseEPSS 0.5%CVE-2023-45149MEDIUMPassword of talk conversations can be bruteforced in NextcloudEPSS 0.5%CVE-2025-47794LOWNextcloud Server vulnerable to insecure temporary file creation, race with write access and permissionEPSS 0.5%CVE-2023-23944LOWNexcloud Mail app temporarily stores cleartext password in databaseEPSS 0.5%CVE-2022-24885LOWImproper Authentication in Nextcloud Android FilesEPSS 0.5%CVE-2019-5453—Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protectiEPSS 0.5%CVE-2026-77169MEDIUMA vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegEPSS 0.5%CVE-2019-5455—Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.EPSS 0.5%