VendorsNextcloudnextcloud_serverall versions
Vulnerabilities

Nextcloud Nextcloud Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2019-15616
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
Published 2020-02-04 · Modified
4.3EPSS 0.008
CVE-2020-8117
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
Published 2020-02-04 · Modified
4.3EPSS 0.007
CVE-2023-45148
Rate limiter not working reliable when Memcached is installed in Nextcloud
Published 2023-10-16 · Modified
4.3EPSS 0.007
CVE-2020-8122
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
Published 2020-02-04 · Modified
4.3EPSS 0.007
CVE-2017-0884
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.
Published 2017-04-05 · Modified
4.3EPSS 0.007
CVE-2022-24889
Insufficient Verification of Data Authenticity in Nextcloud Server
Published 2022-04-27 · Modified
4.3EPSS 0.007
CVE-2023-48304
Nextcloud Server vulnerable to attacker enabling/disabling birthday calendar for any user
Published 2023-11-21 · Modified
4.3EPSS 0.006
CVE-2023-39961
Text does not respect "Allow download" permissions
Published 2023-08-10 · Modified
4.3EPSS 0.006
CVE-2024-52513
Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares
Published 2024-11-15 · Analyzed
4.3EPSS 0.005
CVE-2025-47794
Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permission
Published 2025-05-16 · Analyzed
4.3EPSS 0.005
CVE-2024-37315
Nextcloud Server's read-only users can restore old versions
Published 2024-06-14 · Modified
4.3EPSS 0.004
CVE-2024-52516
Nextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of them
Published 2024-11-15 · Analyzed
4.3EPSS 0.004
CVE-2025-66552
Nextcloud Server admin_audit does not log all actions on files in groupfolders
Published 2025-12-05 · Analyzed
4.3EPSS 0.003
CVE-2025-66547
Nextcloud Server users can modify tags on files that do not belong to them
Published 2025-12-05 · Analyzed
4.3EPSS 0.003
CVE-2025-64011
Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.
Published 2025-12-12 · Analyzed
4.3EPSS 0.003
CVE-2024-52514
Nextcloud Server allows users to copy folder that contain files that are blocked by the files access control
Published 2024-11-15 · Analyzed
4.1EPSS 0.005
CVE-2020-8150
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
Published 2020-11-09 · Modified
4.1EPSS 0.003
CVE-2021-32653
Default settings leak federated cloud ID to lookup server of all users
Published 2021-06-01 · Modified
4.0EPSS 0.012
CVE-2024-22403
OAuth2 authorization codes are valid indefinetly in Nextcloud server
Published 2024-01-18 · Modified
3.7EPSS 0.005
CVE-2018-16463
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Published 2018-10-30 · Modified
3.6EPSS 0.005
CVE-2021-32655
Files Drop public link can be added as federated share
Published 2021-06-01 · Modified
3.5EPSS 0.010
CVE-2017-0895
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
Published 2017-05-08 · Modified
3.5EPSS 0.007
CVE-2024-37314
Nextcloud Photos' shared albums have no restriction on photo removal
Published 2024-06-14 · Modified
3.5EPSS 0.004
CVE-2024-37887
Nextcloud Server's events information leaked with shared calendars on recurrence exceptions
Published 2024-06-14 · Analyzed
3.5EPSS 0.004
CVE-2020-8173
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
Published 2020-10-30 · Modified
3.5EPSS 0.004
CVE-2021-32680
Audit log is not properly logging unsetting of share expiration date
Published 2021-07-12 · Modified
3.3EPSS 0.004
CVE-2022-31120
Federated share accepting/declining is not logged in audit log in Nextcloud Server
Published 2022-08-04 · Modified
2.7EPSS 0.009
CVE-2022-41969
Nextcloud Server has no password length limit when creating a user as an administrator
Published 2022-12-01 · Modified
2.7EPSS 0.008
CVE-2023-48303
Nextcloud Server admins can change authentication details of user configured external storage
Published 2023-11-21 · Modified
2.7EPSS 0.007
← Prev5 / 5