Skip to main content

Vendor/product archive

nextcloud / calendar CVEs

Beta · best-effort

10 CVEs tagged to nextcloud / calendar0 Critical, 0 High, 7 Medium, 3 Low, 0 Unrated.

CVE-2026-45286

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-66550

Published Dec 5, 2025

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download li…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66546

Published Dec 5, 2025

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66511

Published Dec 5, 2025

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37316

Published Jun 14, 2024

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clic…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48308

Published Dec 22, 2023

Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45150

Published Oct 16, 2023

Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email address…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33183

Published May 30, 2023

Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24838

Published Apr 11, 2022

Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not san…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3763

Published Jul 5, 2018

In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1