Skip to main content

Vendor/product archive

nextcloud / contacts CVEs

Beta · best-effort

7 CVEs tagged to nextcloud / contacts0 Critical, 0 High, 5 Medium, 1 Low, 1 Unrated.

CVE-2025-66554

Published Dec 5, 2025

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33182

Published May 30, 2023

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2021-39221

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vul…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8281

Published Jan 6, 2021

A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8280

Published Jan 6, 2021

A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3764

Published Jul 5, 2018

In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitizat…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1