skjnldsv

2 exploits Active since Dec 2025
CVE-2025-66512 WRITEUP MEDIUM WRITEUP
Nextcloud Server <31.0.12-32.0.3 - Info Disclosure
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.
CVSS 5.4
CVE-2025-66547 WRITEUP MEDIUM WRITEUP
Nextcloud Server <31.0.1 - Info Disclosure
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
CVSS 4.3