Showing 2 vulnerabilities on this page for OwnCloud

Signals CISA KEV Ransomware Nuclei
owncloud vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

OwnCloud 8.1.8 - Username Disclosure

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.

CWE-203Feb 12, 2026
CVSS5.3v4.0EPSS0.406%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.

CWE-79Nov 22, 2019
CVSS6.1v3.1EPSS0.95%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX