Skip to main content

Vendor/product archive

nextcloud / nextcloud_server CVEs

Beta · best-effort

189 CVEs tagged to nextcloud / nextcloud_server3 Critical, 28 High, 114 Medium, 44 Low, 0 Unrated.

CVE-2026-45810

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45691

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (creat…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45690

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulner…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45285

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextclou…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45283

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not prop…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45282

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can a…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45281

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other use…

CVSS 8.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45279

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the templ…

CVSS 4.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-64011

Published Dec 12, 2025

Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files be…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66552

Published Dec 5, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66547

Published Dec 5, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not h…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66512

Published Dec 5, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66510

Published Dec 5, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3,…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59788

Published Dec 4, 2025

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47794

Published May 16, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13,…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47791

Published May 16, 2025

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 3…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47790

Published May 16, 2025

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52514

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be ab…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52513

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52525

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52523

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds th…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52521

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with ar…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52520

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than int…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52519

Published Nov 15, 2024

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the databas…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 189 CVEsPage 1 of 8