<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nextcloud</title>
  <link>https://cvedaily.com/pages/tags/nextcloud.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nextcloud.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nextcloud</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:35 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-45810 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45810</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45810</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file comment, to read the content of all comments. It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3. It is recommended that the Nextcloud Enterpr…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45722 – Nextcloud is an open source content collaboration platform. From versions 0.9.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45722</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45722</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45691 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45691</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45691</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion) could be reused as a Bearer token to authenticate against DAV endpoints, granting read/write access and bypassing mandatory two-factor authenticatio…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45690 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45690</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45690</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circumvent two-factor authentication (2FA) protections. When a user initiated login with valid credentials on a 2FA-enabled account, the system created a t…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45545 – Nextcloud is an open source content collaboration platform. From versions 0.7.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45545</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45545</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitat…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45544 – Nextcloud is an open source content collaboration platform. From version 0.8.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45544</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45544</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45543 – Nextcloud is an open source content collaboration platform. From version 4.3.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45543</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45543</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45286 – Nextcloud is an open source content collaboration platform. From versions 5.5.13...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45286</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45286</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint for suggesting attendees. The sharing restrictions, applied to other endpoints, were not effective here. This issue has been patched in versions 5.5.17 and 6.2.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45285 – Nextcloud is an open source content collaboration platform. From versions 32.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45285</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45285</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45284 – Nextcloud is an open source content collaboration platform. From version 1.3.6 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45284</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45284</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45283 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45283</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45283</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated user could lock or unlock files belonging to other users by targeting their absolute WebDAV paths. Additionally, lock to…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45282 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45282</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45282</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when knowing the share token, circumventing password protection or download restrictions. It is applicable to any file that is shared directly, as the attacker only needs to know a docume…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45281 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45281</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45281</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45279 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45279</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45279</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is u…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45278 – Nextcloud is an open source content collaboration platform. From version 6.1.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45278</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45278</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45277 – Nextcloud is an open source content collaboration platform. Prior to version 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45277</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45277</strong></p>
  <p>Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45275 – Nextcloud is an open source content collaboration platform. Prior to version 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45275</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45275</strong></p>
  <p>Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45267 – Nextcloud is an open source content collaboration platform. Prior to version 5.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45267</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45267</strong></p>
  <p>Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45266 – Nextcloud is an open source content collaboration platform. Prior to versions 21...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45266</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45266</strong></p>
  <p>Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45264 – Nextcloud is an open source content collaboration platform. From versions 17.0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45264</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45264</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename files in the team folder. This issue has been patched in versions 17.0.15, 18.1.12, 19.1.16, 20.1.…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45159 – Nextcloud is an open source content collaboration platform. From versions 1.15.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45159</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45159</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end encrypted folders of the share owner. Reading and modifying of other files was not possible. This i…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45157 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45157</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45157</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporary part files during on going uploads. It is recommended that the Nextcloud Server is upgraded to 32…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45156 – Nextcloud is an open source content collaboration platform. From versions 0.3.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45156</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45156</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45155 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45155</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45155</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circles. Since circle IDs have 62^15 complexity by default this is still unlikely to be executable at will, but if access to an ID was available via anothe…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45154 – Nextcloud is an open source content collaboration platform. From version 2.6.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45154</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45154</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45153 – Nextcloud is an open source content collaboration platform. From version 33.0.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45153</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45153</strong></p>
  <p>Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44515 – Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud New...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44515</guid>
    <pubDate>Thu, 14 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44515</strong></p>
  <p>Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versions, an authenticated attacker could provide a URL pointing to internal/private IP ranges or localhost, causing the Nextcloud server to perform server-side HTTP requests to attacker-controlled destina…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35624 – OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35624</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35624</strong></p>
  <p>OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33580 – OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33580</guid>
    <pubDate>Tue, 31 Mar 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33580</strong></p>
  <p>OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28503 – Tandoor Recipes is an application for managing recipes, planning meals, and buil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28503</guid>
    <pubDate>Thu, 26 Mar 2026 19:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28503</strong></p>
  <p>Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903) fetches a Sync object using `get_object_or_404(Sync, pk=pk)` without including `space=request.space` in the filter. This allows an admin user in Space A to trigger sync operations (Drop…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28449 – OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Tal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28449</guid>
    <pubDate>Thu, 19 Mar 2026 02:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28449</strong></p>
  <p>OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28474 – OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28474</guid>
    <pubDate>Thu, 05 Mar 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28474</strong></p>
  <p>OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25368 – OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25368</guid>
    <pubDate>Sun, 15 Feb 2026 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25368</strong></p>
  <p>OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64011 – Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (ID...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64011</guid>
    <pubDate>Fri, 12 Dec 2025 17:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64011</strong></p>
  <p>Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating the fileId parameter. This allows unauthorized disclosure of sensitive data, such as text files or images, without prior sharing permissions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66558 – Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66558</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66558</strong></p>
  <p>Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to register a new device on the next login. The attacker can not authenticate as the…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66557 – Nextcloud Deck is a kanban style organization tool aimed at personal planning an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66557</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66557</strong></p>
  <p>Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify the permissions of other recipients. This vulnerability is fixed in 1.14.6 and 1.15.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66556 – Nextcloud talk is a video &amp; audio conferencing app for Nextcloud. Prior to 20.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66556</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66556</strong></p>
  <p>Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66554 – Contacts app for Nextcloud easily syncs contacts from various devices with your ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66554</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66554</strong></p>
  <p>Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66553 – Nextcloud Tables allows you to create your own tables with individual columns. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66553</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66553</strong></p>
  <p>Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66551 – Nextcloud Tables allows you to create your own tables with individual columns. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66551</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66551</strong></p>
  <p>Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66549 – Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, whe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66549</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66549</strong></p>
  <p>Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66548 – Nextcloud Deck is a kanban style organization tool aimed at personal planning an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66548</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66548</strong></p>
  <p>Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a different extension than what is displayed. This vulnerability is fixed in 1.12.7, 1.14.4, and 1.15.1.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66545 – Nextcloud Groupfolders provides admin-configured folders shared by everyone in a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66545</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66545</strong></p>
  <p>Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-707</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66515 – The Nextcloud Approval app allows approval or disapproval of files in the sideba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66515</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66515</strong></p>
  <p>The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1 and 2.5.0.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66514 – Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66514</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66514</strong></p>
  <p>Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66513 – Nextcloud Tables allows you to create your own tables with individual columns. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66513</guid>
    <pubDate>Fri, 05 Dec 2025 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66513</strong></p>
  <p>Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66552 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66552</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66552</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-778</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66550 – Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66550</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66550</strong></p>
  <p>Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vulnerability is fixed in 4.7.17 and 5.2.4.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-241</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66547 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66547</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66547</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66546 – Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66546</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66546</strong></p>
  <p>Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66512 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66512</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66512</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66511 – Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66511</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66511</strong></p>
  <p>Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely random generated. This vulnerability is fixed in 6.0.3.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66510 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66510</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66510</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are…</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59788 – Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59788</guid>
    <pubDate>Thu, 04 Dec 2025 19:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59788</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66208 – Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66208</guid>
    <pubDate>Wed, 03 Dec 2025 19:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66208</strong></p>
  <p>Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy. Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php and a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58051 – Nextcloud Tables allows you to create your own tables with individual columns. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58051</guid>
    <pubDate>Thu, 16 Oct 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58051</strong></p>
  <p>Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-841</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-47794 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47794</guid>
    <pubDate>Fri, 16 May 2025 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-47794</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47793 – Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Group...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47793</guid>
    <pubDate>Fri, 16 May 2025 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47793</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47792 – Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47792</guid>
    <pubDate>Fri, 16 May 2025 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47792</strong></p>
  <p>Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47791 – Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47791</guid>
    <pubDate>Fri, 16 May 2025 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47791</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server. The endpoint was removed in Nextcloud Server 28.0.13, 29.0.10, and 30.0.3 and Next…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47790 – Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47790</guid>
    <pubDate>Fri, 16 May 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47790</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirmation after a successful login with the username and password when the server was configured with `re…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52514 – Nextcloud Server is a self hosted personal cloud system. After a user received a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52514</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52514</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access the blocked files depending on the user access control rules. It is recommended that the Nextcloud Server is upgraded to…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52513 – Nextcloud Server is a self hosted personal cloud system. After receiving a "File...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52513</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52513</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52512 – user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52512</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52512</strong></p>
  <p>user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52511 – Nextcloud Tables allows users to to create tables with individual columns. By di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52511</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52511</strong></p>
  <p>Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52510 – The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52510</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52510</strong></p>
  <p>The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52509 – Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52509</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52509</strong></p>
  <p>Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients. It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52508 – Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52508</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52508</strong></p>
  <p>Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like user@example.tld that does not support auto configuration, and an attacker managed to register autoconfig.tld, the used email details would be send to the server of the attacker. It is recommended that the Nextcloud Mail app is upgraded to 1.…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52507 – Nextcloud Tables allows users to to create tables with individual columns. The i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52507</guid>
    <pubDate>Fri, 15 Nov 2024 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52507</strong></p>
  <p>Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52525 – Nextcloud Server is a self hosted personal cloud system. Under certain condition...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52525</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52525</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended…</p>
  <p><strong>CVSS:</strong> 1.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52523 – Nextcloud Server is a self hosted personal cloud system. After setting up a user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52523</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52523</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2 and…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52521 – Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52521</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52521</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52520 – Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52520</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52520</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52519 – Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52519</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52519</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52518 – Nextcloud Server is a self hosted personal cloud system. After an attacker got a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52518</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52518</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52517 – Nextcloud Server is a self hosted personal cloud system. After storing "Global c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52517</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52517</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-52516 – Nextcloud Server is a self hosted personal cloud system. When a server is config...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52516</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-52516</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not unshared. It is recommended that the Nextcloud Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6 and Nextcloud Enterprise Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6.</p>
  <p><strong>CVSS:</strong> 3.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52515 – Nextcloud Server is a self hosted personal cloud system. After an admin enables ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52515</guid>
    <pubDate>Fri, 15 Nov 2024 17:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52515</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated SVG file referencing paths. If the file would exist the preview of the SVG would preview the other file instead. It is recommended that the Nextcloud Server is upgraded to 27.1.10, 28.0.6 or 29.0.1 and Nextcloud Enterprise Server is…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-46958 – In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46958</guid>
    <pubDate>Mon, 16 Sep 2024 02:15:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-46958</strong></p>
  <p>In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-37887 – Nextcloud Server is a self hosted personal cloud system. Private shared calendar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37887</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-37887</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37886 – user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37886</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37886</strong></p>
  <p>user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-37885 – The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37885</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-37885</strong></p>
  <p>The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-37884 – Nextcloud Server is a self hosted personal cloud system. A malicious user was ab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37884</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-37884</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37883 – Nextcloud Deck is a kanban style organization tool aimed at personal planning an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37883</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37883</strong></p>
  <p>Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37882 – Nextcloud Server is a self hosted personal cloud system. A recipient of a share ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37882</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37882</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37317 – The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37317</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37317</strong></p>
  <p>The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37316 – Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37316</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37316</strong></p>
  <p>Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-241</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-37315 – Nextcloud Server is a self hosted personal cloud system. An attacker with read-o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37315</guid>
    <pubDate>Fri, 14 Jun 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-37315</strong></p>
  <p>Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-37314 – Nextcloud Photos is a photo management app. Users can remove photos from the alb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37314</guid>
    <pubDate>Fri, 14 Jun 2024 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-37314</strong></p>
  <p>Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37313 – Nextcloud server is a self hosted personal cloud system. Under some circumstance...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37313</guid>
    <pubDate>Fri, 14 Jun 2024 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37313</strong></p>
  <p>Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37312 – user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37312</guid>
    <pubDate>Fri, 14 Jun 2024 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37312</strong></p>
  <p>user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22404 – Nextcloud files Zip app is a tool to create zip archives from one or multiple fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22404</guid>
    <pubDate>Thu, 18 Jan 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22404</strong></p>
  <p>Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22402 – Nextcloud guests app is a utility to create guest users which can only see files...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22402</guid>
    <pubDate>Thu, 18 Jan 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22402</strong></p>
  <p>Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22401 – Nextcloud guests app is a utility to create guest users which can only see files...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22401</guid>
    <pubDate>Thu, 18 Jan 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22401</strong></p>
  <p>Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22403 – Nextcloud server is a self hosted personal cloud system. In affected versions OA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22403</guid>
    <pubDate>Thu, 18 Jan 2024 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22403</strong></p>
  <p>Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated. To exploit this vulnerability an attacker would need to intercept an OAuth code…</p>
  <p><strong>CVSS:</strong> 3.0 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22400 – Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22400</guid>
    <pubDate>Thu, 18 Jan 2024 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22400</strong></p>
  <p>Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22213 – Deck is a kanban style organization tool aimed at personal planning and project ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22213</guid>
    <pubDate>Thu, 18 Jan 2024 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22213</strong></p>
  <p>Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerabi…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22212 – Nextcloud Global Site Selector is a tool which allows you to run multiple small ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22212</guid>
    <pubDate>Thu, 18 Jan 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22212</strong></p>
  <p>Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49792 – Nextcloud Server provides data storage for Nextcloud, an open source cloud platf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49792</guid>
    <pubDate>Fri, 22 Dec 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49792</strong></p>
  <p>Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trusted proxy the server could be tricked into reading a wrong remote address for an attacker, allowing th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49791 – Nextcloud Server provides data storage for Nextcloud, an open source cloud platf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49791</guid>
    <pubDate>Fri, 22 Dec 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49791</strong></p>
  <p>Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages to get access to an active session of another user via another way, they could delete and modify workflows by sending cal…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49791">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
