Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Nextcloud Subscribe
Filtered by product Nextcloud
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15622 1 Nextcloud 1 Nextcloud 2020-02-12 2.1 LOW 2.4 LOW
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
CVE-2019-15614 1 Nextcloud 1 Nextcloud 2020-02-12 3.5 LOW 5.4 MEDIUM
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
CVE-2019-15611 1 Nextcloud 1 Nextcloud 2020-02-11 4.0 MEDIUM 4.9 MEDIUM
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
CVE-2020-8120 1 Nextcloud 1 Nextcloud 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
CVE-2016-9460 2 Nextcloud, Owncloud 2 Nextcloud, Owncloud 2017-04-03 5.0 MEDIUM 5.3 MEDIUM
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.