owncloud Vulnerabilities and Affected Products
Vulnerabilities associated with OwnCloud.
Products
Clear product- ownCloud 104 vulnerabilities
- Android2 vulnerabilities
- OwnCloud2 vulnerabilities
- anroid_apk1 vulnerability
- Anti-Virus for ownCloud1 vulnerability
- DrawIO for ownCloud1 vulnerability
- guests1 vulnerability
- ownCloud Core1 vulnerability
- ownCloud graphapi1 vulnerability
- ownCloud Server1 vulnerability
- SharePoint1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25337MEDIUM | OwnCloud 8.1.8 - Username DisclosureOwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information. CWE-203Feb 12, 2026 | CVSS5.3v4.0 | EPSS0.406% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2013-0202MEDIUM | Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php. CWE-79Nov 22, 2019 | CVSS6.1v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |