VendorsNextcloudnextcloud_serverany version
Vulnerabilities

Nextcloud Nextcloud Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

184CVEs
CVE-2017-0884
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.
Published 2017-04-05 · Modified
4.3EPSS 0.007
CVE-2022-24889
Insufficient Verification of Data Authenticity in Nextcloud Server
Published 2022-04-27 · Modified
4.3EPSS 0.007
CVE-2023-48304
Nextcloud Server vulnerable to attacker enabling/disabling birthday calendar for any user
Published 2023-11-21 · Modified
4.3EPSS 0.006
CVE-2023-39961
Text does not respect "Allow download" permissions
Published 2023-08-10 · Modified
4.3EPSS 0.006
CVE-2024-52513
Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares
Published 2024-11-15 · Analyzed
4.3EPSS 0.005
CVE-2025-47794
Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permission
Published 2025-05-16 · Analyzed
4.3EPSS 0.005
CVE-2024-37315
Nextcloud Server's read-only users can restore old versions
Published 2024-06-14 · Modified
4.3EPSS 0.004
CVE-2024-52516
Nextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of them
Published 2024-11-15 · Analyzed
4.3EPSS 0.004
CVE-2025-66552
Nextcloud Server admin_audit does not log all actions on files in groupfolders
Published 2025-12-05 · Analyzed
4.3EPSS 0.003
CVE-2025-66547
Nextcloud Server users can modify tags on files that do not belong to them
Published 2025-12-05 · Analyzed
4.3EPSS 0.003
CVE-2024-52514
Nextcloud Server allows users to copy folder that contain files that are blocked by the files access control
Published 2024-11-15 · Analyzed
4.1EPSS 0.005
CVE-2020-8150
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
Published 2020-11-09 · Modified
4.1EPSS 0.003
CVE-2021-32653
Default settings leak federated cloud ID to lookup server of all users
Published 2021-06-01 · Modified
4.0EPSS 0.012
CVE-2024-22403
OAuth2 authorization codes are valid indefinetly in Nextcloud server
Published 2024-01-18 · Modified
3.7EPSS 0.005
CVE-2018-16463
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Published 2018-10-30 · Modified
3.6EPSS 0.005
CVE-2021-32655
Files Drop public link can be added as federated share
Published 2021-06-01 · Modified
3.5EPSS 0.010
CVE-2017-0895
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
Published 2017-05-08 · Modified
3.5EPSS 0.007
CVE-2024-37314
Nextcloud Photos' shared albums have no restriction on photo removal
Published 2024-06-14 · Modified
3.5EPSS 0.004
CVE-2024-37887
Nextcloud Server's events information leaked with shared calendars on recurrence exceptions
Published 2024-06-14 · Analyzed
3.5EPSS 0.004
CVE-2020-8173
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
Published 2020-10-30 · Modified
3.5EPSS 0.004
CVE-2021-32680
Audit log is not properly logging unsetting of share expiration date
Published 2021-07-12 · Modified
3.3EPSS 0.004
CVE-2022-31120
Federated share accepting/declining is not logged in audit log in Nextcloud Server
Published 2022-08-04 · Modified
2.7EPSS 0.009
CVE-2022-41969
Nextcloud Server has no password length limit when creating a user as an administrator
Published 2022-12-01 · Modified
2.7EPSS 0.008
CVE-2023-48303
Nextcloud Server admins can change authentication details of user configured external storage
Published 2023-11-21 · Modified
2.7EPSS 0.007
← Prev5 / 5