VendorsNextcloudnextcloud_serverall versions
Vulnerabilities

Nextcloud Nextcloud Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2016-9466
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an attacker could influence the error message, this led to a reflected Cross-Site-Scripting vulnerability.
Published 2017-03-28 · Modified
6.1EPSS 0.017
CVE-2016-9459
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user. The file was delivered with an attachment disposition forcing the browser to download the document. However, Firefox running on Microsoft Windows would offer the user to open the data in the browser as an HTML document. Thus any injected data in the log would be executed.
Published 2017-03-28 · Modified
6.1EPSS 0.015
CVE-2021-32733
XSS in Nextcloud Text application
Published 2021-07-12 · Modified
6.1EPSS 0.011
CVE-2020-8120
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
Published 2020-02-04 · Modified
6.1EPSS 0.009
CVE-2023-35171
Nextcloud Server vulnerable to open redirect on "Unsupported browser" warning
Published 2023-06-23 · Modified
6.1EPSS 0.006
CVE-2025-66512
Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud
Published 2025-12-05 · Analyzed
6.1EPSS 0.003
CVE-2024-52517
Nextcloud Server's global credentials of external storages are sent back to the frontend
Published 2024-11-15 · Analyzed
5.9EPSS 0.006
CVE-2019-15612
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Published 2020-02-04 · Modified
5.9EPSS 0.003
CVE-2026-45691
Nextcloud: Bypass of second factor authentication on DAV endpoints
Published 2026-06-01 · Analyzed
5.9EPSS 0.003
CVE-2026-45690
Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay
Published 2026-06-01 · Analyzed
5.9EPSS 0.003
CVE-2023-39958
Missing brute force protection on password reset token OAuth2 API controller
Published 2023-08-10 · Modified
5.8EPSS 0.007
CVE-2018-16464
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
Published 2018-10-30 · Modified
5.7EPSS 0.009
CVE-2017-0936
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.
Published 2018-03-28 · Modified
5.7EPSS 0.008
CVE-2019-15617
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
Published 2020-02-04 · Modified
5.5EPSS 0.006
CVE-2021-32801
Exceptions may have logged Encryption-at-Rest key content in Nextcloud server
Published 2021-09-07 · Modified
5.5EPSS 0.002
CVE-2022-31014
SMTP Command Injection in iCalendar Attachments to emails via newlines in Nextcloud Server
Published 2022-07-05 · Modified
5.4EPSS 0.025
CVE-2016-7419
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.
Published 2016-09-17 · Modified
5.4EPSS 0.014
CVE-2020-8155
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
Published 2020-05-12 · Modified
5.4EPSS 0.011
CVE-2016-9465
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to not performing any kind of verification on the image content this is prone to a stored Cross-Site Scripting attack.
Published 2017-03-28 · Modified
5.4EPSS 0.011
CVE-2020-8294
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
Published 2021-02-03 · Modified
5.4EPSS 0.009
CVE-2018-3780
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
Published 2018-08-13 · Modified
5.4EPSS 0.009
CVE-2017-0890
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.
Published 2017-05-08 · Modified
5.4EPSS 0.007
CVE-2017-0891
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.
Published 2017-05-08 · Modified
5.4EPSS 0.006
CVE-2017-0893
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.
Published 2017-05-08 · Modified
5.4EPSS 0.006
CVE-2023-48301
Nextcloud Server HTML injection in search UI when selecting a circle with HTML in the display name
Published 2023-11-21 · Modified
5.4EPSS 0.006
CVE-2023-49791
Workflows do not require password confirmation on API level
Published 2023-12-22 · Modified
5.4EPSS 0.006
CVE-2023-48302
Nextcloud Server vulnerable to Self XSS when pasting HTML into Text app with Ctrl+Shift+V
Published 2023-11-21 · Modified
5.4EPSS 0.006
CVE-2024-52518
Nextcloud Server is missing password confirmation when changing external storage options
Published 2024-11-15 · Analyzed
5.4EPSS 0.005
CVE-2024-37884
Nextcloud Server's users can delete old versions of read-only shared files
Published 2024-06-14 · Modified
5.4EPSS 0.004
CVE-2016-9467
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.
Published 2017-03-28 · Modified
5.3EPSS 0.030
CVE-2016-9468
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
Published 2017-03-28 · Modified
5.3EPSS 0.021
CVE-2019-15623
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
Published 2020-02-04 · Modified
5.3EPSS 0.019
CVE-2021-32703
Lack of ratelimit on shareinfo endpoint
Published 2021-07-12 · Modified
5.3EPSS 0.015
CVE-2021-32734
File path disclosure of shared files in Nextcloud Text application
Published 2021-07-12 · Modified
5.3EPSS 0.014
CVE-2021-32678
Ratelimit not applied on OCS API responses
Published 2021-07-12 · Modified
5.3EPSS 0.014
CVE-2021-32766
Nextcloud Text app can disclose existence of folders in "File Drop" link share
Published 2021-09-07 · Modified
5.3EPSS 0.013
CVE-2021-32741
Lack of ratelimit on public share link mount endpoint
Published 2021-07-12 · Modified
5.3EPSS 0.013
CVE-2018-3776
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
Published 2018-08-12 · Modified
5.3EPSS 0.013
CVE-2021-32725
Default share permissions not respected for federated reshares
Published 2021-07-12 · Modified
5.3EPSS 0.012
CVE-2021-41239
User enumeration setting not respected in Nextcloud server
Published 2022-03-08 · Modified
5.3EPSS 0.011
← Prev3 / 5Next →