VendorsNextcloudnextcloud_serverany version
Vulnerabilities

Nextcloud Nextcloud Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

184CVEs
CVE-2021-32802
Preview generation used third-party library not suited for user-generated content in Nextcloud server
Published 2021-09-07 · Modified
10.0EPSS 0.026
CVE-2021-32726
Webauthn tokens not removed after user has been deleted
Published 2021-07-12 · Modified
9.8EPSS 0.018
CVE-2021-22915
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.
Published 2021-06-11 · Modified
9.8EPSS 0.017
CVE-2023-49792
Bruteforce protection can be bypassed with misconfigured proxy
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-48306
Nextcloud Server DNS pin middleware can be tricked into DNS rebinding allowing SSRF
Published 2023-11-21 · Modified
9.8EPSS 0.008
CVE-2021-32654
Attacker can obtain write access to any federated share/public link
Published 2021-06-01 · Modified
9.1EPSS 0.018
CVE-2023-35172
Nextcloud Server password reset endpoint is not brute force protected
Published 2023-06-23 · Modified
9.1EPSS 0.009
CVE-2023-26482
Scope of workflow operations is not validated in nextcloud server
Published 2023-03-30 · Modified
9.0EPSS 0.042
CVE-2021-32688
Application specific tokens can change their own scope
Published 2021-07-12 · Modified
8.8EPSS 0.023
CVE-2021-32679
Filenames not escaped by default in controllers using DownloadResponse
Published 2021-07-12 · Modified
8.8EPSS 0.014
CVE-2018-3775
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
Published 2018-08-12 · Modified
8.8EPSS 0.012
CVE-2023-35928
Nextcloud user scoped external storage can be used to gather credentials of other users
Published 2023-06-23 · Modified
8.8EPSS 0.010
CVE-2023-28643
Potential share collision for recipients when caching is enabled in nextcloud server
Published 2023-03-30 · Modified
8.8EPSS 0.008
CVE-2023-28833
Unrestricted filenames for logo or favicon as admin in the theming settings in nextcloud server
Published 2023-03-30 · Modified
8.8EPSS 0.008
CVE-2023-30539
Users can set up workflows using restricted and invisible system tags in Nextcloud
Published 2023-04-17 · Modified
8.8EPSS 0.006
CVE-2023-45151
OAuth2 client_secret stored in plain text in the Nextcloud database
Published 2023-10-16 · Modified
8.8EPSS 0.005
CVE-2023-32320
Nextcloud Server's brute force protection allows someone to send more requests than intended
Published 2023-06-22 · Modified
8.7EPSS 0.009
CVE-2021-32656
Trusted servers exchange can be triggered by attacker
Published 2021-06-01 · Modified
8.6EPSS 0.018
CVE-2023-48239
Nextcloud Server users can make external storage mount points inaccessible for other users
Published 2023-11-21 · Modified
8.5EPSS 0.010
CVE-2024-52519
Nextcloud Server's OAuth2 client secrets were stored in a recoverable way
Published 2024-11-15 · Analyzed
8.2EPSS 0.005
CVE-2016-9463
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.
Published 2017-03-28 · Modified
8.1EPSS 0.041
CVE-2021-32800
Bypass of Two Factor Authentication in Nextcloud server
Published 2021-09-07 · Modified
8.1EPSS 0.018
CVE-2018-3761
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
Published 2018-07-05 · Modified
8.1EPSS 0.017
CVE-2021-41177
Rate-limits not working on instances without configured memory cache backend
Published 2021-10-25 · Modified
8.1EPSS 0.016
CVE-2020-8121
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
Published 2020-02-04 · Modified
8.1EPSS 0.010
CVE-2018-16466
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
Published 2018-10-30 · Modified
8.1EPSS 0.010
CVE-2023-35927
Nextcloud system addressbooks can be modified by malicious trusted server
Published 2023-06-23 · Modified
8.1EPSS 0.008
CVE-2020-8259
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
Published 2020-11-16 · Modified
8.1EPSS 0.007
CVE-2023-32319
Basic auth header on WebDAV requests is not brute-force protected in Nextcloud
Published 2023-05-26 · Modified
8.1EPSS 0.007
CVE-2023-25817
Delete permissions are not saved when creating public share in Nextcloud server
Published 2023-03-27 · Modified
8.1EPSS 0.006
CVE-2024-37882
Nextcloud Server can reshare read&share only folder with more permissions
Published 2024-06-14 · Modified
8.1EPSS 0.005
CVE-2026-45281
Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update
Published 2026-06-01 · Analyzed
8.1EPSS 0.005
CVE-2023-39963
Missing password confirmation when creating app passwords
Published 2023-08-10 · Modified
8.1EPSS 0.003
CVE-2019-15613
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
Published 2020-02-04 · Modified
8.0EPSS 0.011
CVE-2023-25820
Nextcloud Server and Enterprise Server missing brute force protection on password confirmation modal
Published 2023-03-22 · Modified
7.8EPSS 0.002
CVE-2020-8154
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
Published 2020-05-12 · Modified
7.7EPSS 0.018
CVE-2023-39962
Users can delete external storage mount points
Published 2023-08-10 · Modified
7.7EPSS 0.010
CVE-2020-8183
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
Published 2020-10-30 · Modified
7.5EPSS 0.019
CVE-2020-8295
A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.
Published 2021-01-26 · Modified
7.5EPSS 0.018
CVE-2021-32705
Lack of ratelimit on public DAV endpoint
Published 2021-07-12 · Modified
7.5EPSS 0.017
1 / 5Next →