VendorsNextclouddesktopall versions
Vulnerabilities

Nextcloud Desktop

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2024-46958
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
Published 2024-09-16 · Modified
9.1EPSS 0.006
CVE-2021-22879
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Published 2021-04-14 · Modified
8.8EPSS 0.047
CVE-2023-22472
Nextcloud Deck Desktop Client is vulnerable to Cross-Site Request Forgery (CSRF) via malicious link
Published 2023-01-09 · Modified
8.8EPSS 0.002
CVE-2020-8224
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
Published 2020-08-10 · Modified
7.8EPSS 0.007
CVE-2022-41882
Nextcloud Desktop vulnerable to code injection via malicious link
Published 2022-11-11 · Modified
7.8EPSS 0.005
CVE-2024-37885
Code injection in Nextcloud Desktop Client for macOS
Published 2024-06-14 · Modified
7.8EPSS 0.003
CVE-2020-8225
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
Published 2020-09-18 · Modified
7.5EPSS 0.009
CVE-2024-52510
Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
Published 2024-11-15 · Analyzed
7.5EPSS 0.007
CVE-2021-37617
Untrusted Search Path in Nextcloud Desktop Client
Published 2021-08-18 · Modified
7.3EPSS 0.005
CVE-2020-8227
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
Published 2020-08-21 · Modified
7.1EPSS 0.258
CVE-2023-28999
Nextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders
Published 2023-04-04 · Modified
6.9EPSS 0.007
CVE-2023-28997
Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files
Published 2023-04-04 · Modified
6.7EPSS 0.011
CVE-2020-8140
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
Published 2020-03-20 · Modified
6.7EPSS 0.007
CVE-2023-28998
Nextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keys
Published 2023-04-04 · Modified
6.7EPSS 0.007
CVE-2021-32728
End-to-end encryption device setup did not verify public key
Published 2021-08-18 · Modified
6.5EPSS 0.009
CVE-2023-29000
Nextcloud Desktop client does not verify received singed certificate in end-to-end encryption
Published 2023-04-04 · Modified
6.5EPSS 0.004
CVE-2022-39333
Cross-site scripting (XSS) in Nextcloud Desktop Client
Published 2022-11-25 · Modified
6.1EPSS 0.009
CVE-2023-23942
Self reflected HTML injection in Desktop client
Published 2023-02-06 · Modified
6.1EPSS 0.007
CVE-2025-47792
Nextcloud Desktop 3rdparty applications can create share links via socket API
Published 2025-05-16 · Analyzed
6.1EPSS 0.002
CVE-2021-22895
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
Published 2021-06-11 · Modified
5.9EPSS 0.010
CVE-2020-8229
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
Published 2020-08-10 · Modified
5.5EPSS 0.005
CVE-2020-8230
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
Published 2020-08-17 · Modified
5.5EPSS 0.004
CVE-2020-8189
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
Published 2020-08-21 · Modified
5.4EPSS 0.014
CVE-2022-39332
Cross-site scripting (XSS) in Nextcloud Desktop Client
Published 2022-11-25 · Modified
5.4EPSS 0.009
CVE-2022-39331
Cross-site Scripting (XSS) in Nexcloud Desktop Client
Published 2022-11-25 · Modified
5.4EPSS 0.009
CVE-2022-39334
nextcloudcmd incorrectly trusts bad TLS certificates
Published 2022-11-25 · Modified
4.7EPSS 0.002
CVE-2025-66549
Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end encrypted directory
Published 2025-12-05 · Analyzed
2.7EPSS 0.003