Skip to main content

Vendor/product archive

nextcloud / deck CVEs

Beta · best-effort

17 CVEs tagged to nextcloud / deck0 Critical, 2 High, 10 Medium, 4 Low, 1 Unrated.

CVE-2025-66557

Published Dec 5, 2025

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66548

Published Dec 5, 2025

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-37883

Published Jun 14, 2024

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22213

Published Jan 18, 2024

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2023-22471

Published Jan 14, 2023

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete att…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22470

Published Jan 14, 2023

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated poten…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22469

Published Jan 10, 2023

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29159

Published May 20, 2022

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24906

Published May 20, 2022

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is reco…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-39225

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to ac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37631

Published Sep 7, 2021

Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck applic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22913

Published Jun 11, 2021

Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Ne…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8297

Published Feb 23, 2021

Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a prev…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8235

Published Oct 5, 2020

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8182

Published Oct 5, 2020

Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8179

Published Jul 2, 2020

Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1