VendorsNextclouddeckany version
Vulnerabilities

Nextcloud Deck any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2021-39225
Missing permission check on Deck API
Published 2021-10-25 · Modified
8.1EPSS 0.013
CVE-2021-22913
Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.
Published 2021-06-11 · Modified
6.5EPSS 0.014
CVE-2021-37631
Circle can be accessed by non-Circle members in Nextcloud Deck
Published 2021-09-07 · Modified
6.5EPSS 0.013
CVE-2023-22470
Nextcloud Deck vulnerable to uncontrolled resource consumption
Published 2023-01-14 · Modified
6.5EPSS 0.007
CVE-2023-22469
Nextcloud Deck card vulnerable to data leak to unauthorized users via reference preview cache
Published 2023-01-10 · Modified
5.8EPSS 0.007
CVE-2025-66548
Nextcloud Deck app allows to spoof file extensions by using RTLO characters
Published 2025-12-05 · Analyzed
5.5EPSS 0.002
CVE-2024-22213
Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app
Published 2024-01-18 · Modified
5.4EPSS 0.005
CVE-2025-66557
Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners
Published 2025-12-05 · Analyzed
5.4EPSS 0.003
CVE-2022-29159
Possibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud Deck
Published 2022-05-20 · Modified
5.0EPSS 0.010
CVE-2019-15619
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
Published 2020-02-04 · Modified
4.8EPSS 0.008
CVE-2020-8297
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.
Published 2021-02-23 · Modified
4.3EPSS 0.013
CVE-2022-24906
Error in deleting deck cards attachment reveals the full application path in Nextcloud Deck
Published 2022-05-20 · Modified
4.3EPSS 0.011
CVE-2023-22471
Nextcloud Deck vulnerable to authorization bypass
Published 2023-01-14 · Modified
4.3EPSS 0.005
CVE-2024-37883
Nextcloud Deck can access comments and attachments of deleted cards
Published 2024-06-14 · Modified
4.3EPSS 0.004
CVE-2020-8179
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
Published 2020-07-02 · Modified
4.1EPSS 0.006