VendorsNextcloudnextcloud_serverany version
Vulnerabilities

Nextcloud Nextcloud Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

184CVEs
CVE-2023-25821
Nextcloud download permissions can be changed by resharer
Published 2023-02-24 · Modified
7.5EPSS 0.009
CVE-2023-28847
Nextcloud Server missing brute force protection for passwords of password protected share links
Published 2023-04-25 · Modified
7.5EPSS 0.008
CVE-2022-36074
Authentication headers exposed on by Nextcloud Server
Published 2022-09-15 · Modified
7.5EPSS 0.008
CVE-2023-28644
Reference fetch can saturate the server bandwidth for 10 seconds in nextcloud server
Published 2023-03-30 · Modified
7.5EPSS 0.006
CVE-2023-39960
Nextcloud Server has improper restriction of excessive authentication attempts on WebDAV endpoint
Published 2023-10-13 · Modified
7.5EPSS 0.006
CVE-2023-28835
Insecure randomness for default password in nextcloud
Published 2023-03-30 · Modified
7.5EPSS 0.005
CVE-2023-25579
Directory traversal in Nextcloud server
Published 2023-02-22 · Modified
7.5EPSS 0.005
CVE-2024-37313
Nextcloud server allows the by-pass the second factor
Published 2024-06-14 · Analyzed
7.5EPSS 0.004
CVE-2024-52525
Nextcloud Server User password is available in memory of the PHP process
Published 2024-11-15 · Analyzed
7.5EPSS 0.003
CVE-2023-32318
User session not correctly destroyed on logout
Published 2023-05-26 · Modified
7.2EPSS 0.002
CVE-2023-25818
Missing brute force protection on password reset token in Nextcloud Server
Published 2023-03-27 · Modified
7.1EPSS 0.006
CVE-2020-8236
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
Published 2020-10-30 · Modified
6.8EPSS 0.006
CVE-2026-45810
Nextcloud: Propfind requests for file comments allowed to load comments for other files
Published 2026-06-01 · Analyzed
6.8EPSS 0.004
CVE-2020-8296
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
Published 2021-03-03 · Modified
6.7EPSS 0.005
CVE-2021-22877
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.
Published 2021-03-03 · Modified
6.5EPSS 0.017
CVE-2022-24741
High memory usage in Nextcloud server
Published 2022-03-09 · Modified
6.5EPSS 0.016
CVE-2020-8293
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
Published 2021-01-26 · Modified
6.5EPSS 0.016
CVE-2020-8139
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
Published 2020-03-20 · Modified
6.5EPSS 0.015
CVE-2020-8138
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
Published 2020-03-20 · Modified
6.5EPSS 0.014
CVE-2023-25816
nextcloud vulnerable to Uncontrolled Resource Consumption
Published 2023-02-24 · Modified
6.5EPSS 0.014
CVE-2017-0886
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.
Published 2017-04-05 · Modified
6.5EPSS 0.012
CVE-2019-15621
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
Published 2020-02-04 · Modified
6.5EPSS 0.011
CVE-2022-39346
Missing length validation of user displayname in nextcloud server
Published 2022-11-25 · Modified
6.5EPSS 0.010
CVE-2023-39952
Advanced permissions not respected when copying entire group folders
Published 2023-08-10 · Modified
6.5EPSS 0.008
CVE-2024-52520
Nextcloud Server's link reference provider can be tricked into downloading bigger files than intended
Published 2024-11-15 · Analyzed
6.5EPSS 0.008
CVE-2021-41233
Missing authorization in Nextcloud text
Published 2022-03-10 · Modified
6.5EPSS 0.008
CVE-2025-47793
Nextcloud Server and Groupfolders app vulnerable to bypass of group folder quota limit using attachment in text file
Published 2025-05-16 · Analyzed
6.5EPSS 0.008
CVE-2022-31118
Missing brute force protection on cloud federation sharing in Nextcloud Server
Published 2022-08-04 · Modified
6.5EPSS 0.007
CVE-2024-52515
Nextcloud Server has incomplete sanitization of SVG files allows to embed other images into previews
Published 2024-11-15 · Analyzed
6.5EPSS 0.007
CVE-2024-52523
Nextcloud Server Custom defined credentials of external storages are sent back to the frontend
Published 2024-11-15 · Analyzed
6.5EPSS 0.006
CVE-2023-28844
User without download rights can download older version of that file in nextcloud server
Published 2023-03-31 · Modified
6.5EPSS 0.006
CVE-2026-45279
Nextcloud: Limited path traversal via template API if using `{lang}` in config
Published 2026-06-01 · Analyzed
6.5EPSS 0.006
CVE-2022-39364
Exception logging in Sharepoint app reveals clear-text connection details
Published 2022-10-27 · Modified
6.5EPSS 0.005
CVE-2026-45282
Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access
Published 2026-06-01 · Analyzed
6.5EPSS 0.005
CVE-2017-0883
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.
Published 2017-04-05 · Modified
6.4EPSS 0.006
CVE-2026-45285
Nextcloud: Hidden Public Link creation when sharing to a Team External Member
Published 2026-06-01 · Analyzed
6.4EPSS 0.005
CVE-2025-47790
Nextcloud Server doesn't request second factor after session timeout
Published 2025-05-16 · Analyzed
6.4EPSS 0.004
CVE-2025-59788
Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.
Published 2025-12-04 · Analyzed
6.4EPSS 0.003
CVE-2026-45283
Nextcloud: Files Lock app allows users to lock and unlock files of other users
Published 2026-06-01 · Analyzed
6.3EPSS 0.004
CVE-2016-9466
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an attacker could influence the error message, this led to a reflected Cross-Site-Scripting vulnerability.
Published 2017-03-28 · Modified
6.1EPSS 0.017
← Prev2 / 5Next →