VendorsNextcloudcontactsall versions
Vulnerabilities

Nextcloud Contacts

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-39221
XSS in Contacts
Published 2021-10-25 · Modified
6.4EPSS 0.005
CVE-2020-8280
A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.
Published 2021-01-06 · Modified
5.4EPSS 0.006
CVE-2020-8281
A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.
Published 2021-01-06 · Modified
5.4EPSS 0.006
CVE-2025-66554
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Published 2025-12-05 · Analyzed
5.4EPSS 0.003
CVE-2018-3764
In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
Published 2018-07-05 · Modified
4.8EPSS 0.006
CVE-2023-33182
Nextcloud Contacts photos only sanitized if mime type is all lower case
Published 2023-05-30 · Modified
4.3EPSS 0.008
CVE-2020-8181
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
Published 2020-07-10 · Modified
4.3EPSS 0.008