Skip to main content

Vendor/product archive

nextcloud / user_oidc CVEs

Beta · best-effort

9 CVEs tagged to nextcloud / user_oidc0 Critical, 1 High, 5 Medium, 3 Low, 0 Unrated.

CVE-2026-45284

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authen…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45278

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, w…

CVSS 3.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-52512

Published Nov 15, 2024

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-37886

Published Jun 14, 2024

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37312

Published Jun 14, 2024

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39954

Published Aug 10, 2023

user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at l…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-39953

Published Aug 10, 2023

user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the is…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32074

Published May 25, 2023

user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgrad…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28848

Published Apr 4, 2023

user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to b…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1