VendorsNextclouduser_oidcany version
Vulnerabilities

Nextcloud User any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-32074
Nextcloud user_oidc app is missing brute force protection
Published 2023-05-25 · Modified
9.8EPSS 0.009
CVE-2026-45284
Nextcloud: Wrong condition in the User OIDC app's LdapService allowed deleted LDAP users to authenticate
Published 2026-06-01 · Analyzed
8.8EPSS 0.002
CVE-2023-39954
user_oidc app stores client secret unencrypted in database
Published 2023-08-10 · Modified
8.1EPSS 0.004
CVE-2024-37312
Nextcloud user_oidc app's ID4me feature is available even when disabled
Published 2024-06-14 · Analyzed
6.3EPSS 0.006
CVE-2024-52512
Nextcloud User OIDC has an open redirection when logging in with User OIDC
Published 2024-11-15 · Analyzed
6.1EPSS 0.004
CVE-2026-45278
Nextcloud: Open Redirect in user_oidc login flow via protocol-relative URL bypass
Published 2026-06-01 · Analyzed
6.1EPSS 0.002
CVE-2023-28848
CSRF protection on user_oidc login returned the expected token in case of an error
Published 2023-04-04 · Modified
5.4EPSS 0.003
CVE-2024-37886
Nextcloud user_oidc's ID4me does not validate signature or expiration
Published 2024-06-14 · Analyzed
5.4EPSS 0.002
CVE-2023-39953
Issuer not verified from obtained token in user_oidc
Published 2023-08-10 · Modified
4.8EPSS 0.005