VendorsNextcloudmailany version
Vulnerabilities

Nextcloud Mail any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-48307
Nextcloud Mail app vulnerable to Server-Side Request Forgery
Published 2023-11-21 · Modified
9.8EPSS 0.009
CVE-2022-31132
Unauthenticated SSRF in 3rd party module "cerdic/csstidy"
Published 2022-08-04 · Modified
9.8EPSS 0.007
CVE-2021-32652
Missing permission check on email metadata retrieval
Published 2021-06-01 · Modified
8.8EPSS 0.011
CVE-2024-52508
Nextcloud Mail auto configurator can be tricked into sending account information to wrong servers
Published 2024-11-15 · Analyzed
8.2EPSS 0.007
CVE-2020-8156
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
Published 2020-05-12 · Modified
7.0EPSS 0.009
CVE-2023-23944
Nexcloud Mail app temporarily stores cleartext password in database
Published 2023-02-06 · Modified
6.5EPSS 0.005
CVE-2024-52509
Nextcloud Mail app does not respect download permissions in shares
Published 2024-11-15 · Analyzed
5.7EPSS 0.005
CVE-2025-66514
Nextcloud Mail stored HTML injection in subject text
Published 2025-12-05 · Analyzed
5.4EPSS 0.003
CVE-2023-33184
Blind SSRF in the Nextcloud Mail app on avatar endpoint
Published 2023-05-27 · Modified
5.3EPSS 0.005
CVE-2023-25160
IDOR Vulnerability in Nextcloud Mail
Published 2023-02-13 · Modified
5.3EPSS 0.005
CVE-2023-23943
Blind SSRF via server URL input in the Nextcloud Mail app
Published 2023-02-06 · Modified
5.0EPSS 0.009
CVE-2022-31119
Password disclosure in log file in Nextcloud Mail App
Published 2022-08-04 · Modified
4.9EPSS 0.008
CVE-2021-32707
Bypass of image blocking in Nextcloud Mail
Published 2021-07-12 · Modified
4.3EPSS 0.011
CVE-2023-45660
Require strict cookies for image proxy requests in Nextcloud Mail
Published 2023-10-16 · Modified
4.3EPSS 0.006
CVE-2021-39220
Bypass of image blocking in Nextcloud Mail
Published 2021-10-25 · Modified
3.5EPSS 0.008