Vulnerabilities in Nextcloud
297 resultsVexday analysis
Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.
CVE-2025-59788MEDIUMCross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0EPSS 0.3%CVE-2026-82980MEDIUMAny authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves fEPSS 0.3%CVE-2025-66549LOWNextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directoryEPSS 0.3%CVE-2025-66511MEDIUMNextcloud Calendar app used predictable proposal participant tokensEPSS 0.3%CVE-2026-44515LOWNextcloud News: Authenticated blind SSRF via feed URLEPSS 0.3%CVE-2025-66513MEDIUMNextcloud Tables app share information not limited to relevant usersEPSS 0.3%CVE-2023-49790MEDIUMApp PIN code can be bypassed in Nextcloud Files iOSEPSS 0.3%CVE-2026-77166LOWThe emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebarEPSS 0.3%CVE-2025-66545LOWNextcloud Groupfolders users with read-only permissions for team folder can restore deleted files from trash binEPSS 0.3%CVE-2025-66512MEDIUMNextcloud Server vulnerable to XSS in SVG images when opened outside of NextcloudEPSS 0.3%CVE-2022-41926LOWNextcloud Talk Android broadcast incorrect permission handlingEPSS 0.3%CVE-2025-66557MEDIUMNextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-ownersEPSS 0.3%CVE-2025-66547MEDIUMNextcloud Server users can modify tags on files that do not belong to themEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2025-66558LOWNextcloud Twofactor WebAuthn app was updated based on public keyEPSS 0.3%CVE-2025-66553MEDIUMNextcloud Tables app allowed users to view columns metadata information of any tableEPSS 0.3%CVE-2023-39963HIGHMissing password confirmation when creating app passwordsEPSS 0.3%CVE-2026-77170MEDIUMThe Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether theEPSS 0.3%CVE-2025-66551MEDIUMNextcloud Tables is missing an ownership check which allows moving columns into tables of other usersEPSS 0.3%CVE-2025-66556LOWNextcloud talk allows participants to blindly delete poll drafts of other users by IDEPSS 0.3%