VendorsNextcloudnextcloud_serverall versions
Vulnerabilities

Nextcloud Nextcloud Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2018-16467
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
Published 2018-10-30 · Modified
5.3EPSS 0.011
CVE-2022-39211
Server-Side Request Forgery (SSRF) via potential filter bypass in Nextcloud Server
Published 2022-09-16 · Modified
5.3EPSS 0.010
CVE-2022-41968
Nextcloud Server's calendar name length not validated before writing to database
Published 2022-12-01 · Modified
5.3EPSS 0.009
CVE-2023-25162
Nextcloud Server vulnerable to SSRF via filter bypass due to lax checking on IPs
Published 2023-02-13 · Modified
5.3EPSS 0.008
CVE-2018-16465
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
Published 2018-10-30 · Modified
5.3EPSS 0.008
CVE-2023-25161
Nextcloud Server's missing rate limiting on password reset functionality allows sending lots of emails
Published 2023-02-13 · Modified
5.3EPSS 0.007
CVE-2020-8133
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
Published 2020-11-09 · Modified
5.3EPSS 0.007
CVE-2022-39329
Profile of disabled user stays accessible
Published 2022-10-27 · Modified
5.3EPSS 0.007
CVE-2022-41970
Nextcloud Server's disabled download shares still allow download through preview images
Published 2022-12-01 · Modified
5.3EPSS 0.006
CVE-2023-39959
Existence of calendars and address books can be checked by unauthenticated users
Published 2023-08-10 · Modified
5.3EPSS 0.006
CVE-2023-25159
Nextcloud Server previews are accessible without a watermark
Published 2023-02-13 · Modified
5.3EPSS 0.005
CVE-2024-52521
Nextcloud Server has a potential hash collision for background jobs could skip queuing them
Published 2024-11-15 · Analyzed
5.3EPSS 0.004
CVE-2025-47791
Nextcloud Server's test remote endpoint is not rate limited
Published 2025-05-16 · Analyzed
5.3EPSS 0.004
CVE-2022-24888
Possible Injection in Nextcloud Server
Published 2022-04-27 · Modified
5.0EPSS 0.013
CVE-2020-8118
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
Published 2020-02-04 · Modified
5.0EPSS 0.013
CVE-2019-15624
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
Published 2020-02-04 · Modified
4.9EPSS 0.015
CVE-2025-66510
Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list
Published 2025-12-05 · Analyzed
4.9EPSS 0.004
CVE-2021-22878
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
Published 2021-03-03 · Modified
4.8EPSS 0.011
CVE-2022-39330
Database resource exhaustion for logged-in users via sharee recommendations with circles
Published 2022-10-27 · Modified
4.8EPSS 0.009
CVE-2019-15619
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
Published 2020-02-04 · Modified
4.8EPSS 0.008
CVE-2019-15618
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
Published 2020-02-04 · Modified
4.8EPSS 0.007
CVE-2019-5451
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
Published 2019-07-30 · Modified
4.6EPSS 0.004
CVE-2020-8152
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.
Published 2020-11-16 · Modified
4.4EPSS 0.003
CVE-2023-48305
Nextcloud Server user_ldap app logs user passwords in the log file on level debug
Published 2023-11-21 · Modified
4.4EPSS 0.002
CVE-2016-9461
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Published 2017-03-28 · Modified
4.3EPSS 0.020
CVE-2016-9462
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.
Published 2017-03-28 · Modified
4.3EPSS 0.019
CVE-2021-32657
Malicious user could break user administration page
Published 2021-06-01 · Modified
4.3EPSS 0.018
CVE-2016-9464
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.
Published 2017-03-28 · Modified
4.3EPSS 0.016
CVE-2017-0888
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.
Published 2017-04-05 · Modified
4.3EPSS 0.015
CVE-2022-29243
Improper input-size validation on the user new session name in Nextcloud Server
Published 2022-05-31 · Modified
4.3EPSS 0.015
CVE-2017-0894
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
Published 2017-05-08 · Modified
4.3EPSS 0.012
CVE-2022-29163
Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Server
Published 2022-05-20 · Modified
4.3EPSS 0.011
CVE-2017-0892
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
Published 2017-05-08 · Modified
4.3EPSS 0.010
CVE-2020-8119
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
Published 2020-02-04 · Modified
4.3EPSS 0.009
CVE-2017-0885
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
Published 2017-04-05 · Modified
4.3EPSS 0.009
CVE-2018-3762
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
Published 2018-07-05 · Modified
4.3EPSS 0.009
CVE-2017-0887
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.
Published 2017-04-05 · Modified
4.3EPSS 0.009
CVE-2019-5449
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
Published 2019-07-30 · Modified
4.3EPSS 0.009
CVE-2021-41241
Advanced permissions is not respected for subfolders in Nextcloud server
Published 2022-03-08 · Modified
4.3EPSS 0.009
CVE-2023-28834
Full path of data directory exposed to Nextcloud server users
Published 2023-04-03 · Modified
4.3EPSS 0.008
← Prev4 / 5Next →