VendorsNextcloudtalkany version
Vulnerabilities

Nextcloud Talk any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-8180
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
Published 2020-06-08 · Modified
9.9EPSS 0.017
CVE-2021-32689
Nextcloud Talk not properly disassociating users from chats after account deletion
Published 2021-07-12 · Modified
8.1EPSS 0.010
CVE-2023-39957
Path traversal allows tricking the Talk Android app into writing files into it's root directory
Published 2023-08-10 · Modified
7.8EPSS 0.004
CVE-2021-32676
Session Fixation in Nextcloud Talk
Published 2021-06-16 · Modified
6.5EPSS 0.010
CVE-2021-39222
XSS in Talk
Published 2021-11-15 · Modified
6.4EPSS 0.011
CVE-2021-41180
Geolocation preview links can be set to arbitrary links in nextcloud talk
Published 2022-03-08 · Modified
6.1EPSS 0.010
CVE-2022-24887
Open Redirect in Nextcloud Talk
Published 2022-04-27 · Modified
6.1EPSS 0.009
CVE-2022-41926
Nextcloud Talk Android broadcast incorrect permission handling
Published 2022-11-25 · Modified
5.5EPSS 0.003
CVE-2018-3781
A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
Published 2018-08-13 · Modified
5.4EPSS 0.007
CVE-2022-35932
Missing rate limit when trying to join a password protected Nextcloud Talk conversation
Published 2022-08-12 · Modified
5.3EPSS 0.013
CVE-2022-39212
Last video frame is still sent after video is disabled in a call in Nextcloud Talk
Published 2022-09-16 · Modified
5.3EPSS 0.007
CVE-2019-15619
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
Published 2020-02-04 · Modified
4.8EPSS 0.008
CVE-2022-24890
Exposure of Private Personal Information to an Unauthorized Actor in Nextcloud Talk
Published 2022-05-17 · Modified
4.3EPSS 0.009
CVE-2023-30540
Chat poll data can still be queried from API after purging history in Nextcloud talk
Published 2023-04-17 · Modified
4.3EPSS 0.007
CVE-2023-45149
Password of talk conversations can be bruteforced in Nextcloud
Published 2023-10-16 · Modified
4.3EPSS 0.005
CVE-2025-66556
Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Published 2025-12-05 · Analyzed
4.3EPSS 0.003
CVE-2019-15620
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
Published 2020-02-04 · Modified
4.0EPSS 0.008
CVE-2023-28845
Chat room membership disclosed via autocompletion in Nextcloud talk
Published 2023-03-31 · Modified
3.5EPSS 0.004
CVE-2021-41181
Nextcloud Talk app exposes chat messages on lockscreen
Published 2022-03-08 · Modified
2.4EPSS 0.003
CVE-2023-22473
Passcode bypass on Talk-Android app
Published 2023-01-09 · Modified
2.1EPSS 0.006