VendorsNextcloudnextcloud_server27.0.0
Vulnerabilities

Nextcloud Nextcloud Server 27.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-45151
OAuth2 client_secret stored in plain text in the Nextcloud database
Published 2023-10-16 · Modified
8.8EPSS 0.005
CVE-2023-39963
Missing password confirmation when creating app passwords
Published 2023-08-10 · Modified
8.1EPSS 0.003
CVE-2023-39962
Users can delete external storage mount points
Published 2023-08-10 · Modified
7.7EPSS 0.010
CVE-2023-39952
Advanced permissions not respected when copying entire group folders
Published 2023-08-10 · Modified
6.5EPSS 0.008
CVE-2023-39958
Missing brute force protection on password reset token OAuth2 API controller
Published 2023-08-10 · Modified
5.8EPSS 0.007
CVE-2023-39959
Existence of calendars and address books can be checked by unauthenticated users
Published 2023-08-10 · Modified
5.3EPSS 0.006
CVE-2023-45148
Rate limiter not working reliable when Memcached is installed in Nextcloud
Published 2023-10-16 · Modified
4.3EPSS 0.007
CVE-2023-39961
Text does not respect "Allow download" permissions
Published 2023-08-10 · Modified
4.3EPSS 0.006