VendorsNextcloudsocialall versions
Vulnerabilities

Nextcloud Social

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-8279
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
Published 2020-11-19 · Modified
7.4EPSS 0.006
CVE-2020-8278
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
Published 2020-11-19 · Modified
5.3EPSS 0.010