Vulnerabilities in Nextcloud

297 results
Vexday analysis

Nextcloud possui 20 vulnerabilidades registradas na base, todas de severidade moderada ou inferior, com destaque para falhas de Cross-Site Scripting (CWE-79). Nenhuma vulnerabilidade está sob ataque ativo conhecido, e não há publicações recentes nos últimos 90 dias, indicando um panorama de risco estável e sem pressão imediata.

CVE-2023-48302LOWNextcloud Server vulnerable to Self XSS when pasting HTML into Text app with Ctrl+Shift+VEPSS 0.6%CVE-2023-25817LOWDelete permissions are not saved when creating public share in Nextcloud serverEPSS 0.6%CVE-2022-36075LOWFile list exposure in Nextcloud Files Access ControlEPSS 0.6%CVE-2023-22473LOWPasscode bypass on Talk-Android appEPSS 0.6%CVE-2026-45156HIGHNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDCEPSS 0.6%CVE-2023-48308LOWCalendar app returns full stacktrace when an error happens while editing appointmentEPSS 0.5%CVE-2023-39953MEDIUMIssuer not verified from obtained token in user_oidcEPSS 0.5%CVE-2023-28835LOWInsecure randomness for default password in nextcloudEPSS 0.5%CVE-2024-37882HIGHNextcloud Server can reshare read&share only folder with more permissionsEPSS 0.5%CVE-2024-52518MEDIUMNextcloud Server is missing password confirmation when changing external storage optionsEPSS 0.5%CVE-2025-58051MEDIUMNextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a tableEPSS 0.5%CVE-2023-33184LOWBlind SSRF in the Nextcloud Mail app on avatar endpointEPSS 0.5%CVE-2024-52513LOWNextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" sharesEPSS 0.5%CVE-2023-22471LOWNextcloud Deck vulnerable to authorization bypassEPSS 0.5%CVE-2021-39221MEDIUMXSS in ContactsEPSS 0.5%CVE-2024-22404MEDIUMPermissions bypass in Nextcloud with the files zip appEPSS 0.5%CVE-2026-45545HIGHNextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL ExecutionEPSS 0.5%CVE-2024-22402MEDIUMImproper handling of request URLs in Nextcloud Guests app allows guest users to bypass app allowlistEPSS 0.5%CVE-2024-52509LOWNextcloud Mail app does not respect download permissions in sharesEPSS 0.5%CVE-2026-45267MEDIUMNextcloud: Missing permission check for from submissionsEPSS 0.5%