nextcloud

359 tracked vulnerabilities.

CVE-2026-44515 LOW
Nextcloud News: Authenticated blind SSRF via feed URL
May 14, 2026
EPSS 0.00
CVE-2026-23696 CRITICAL
Windmill < 1.603.3 File Ownership Handling SQLi RCE
Apr 07, 2026
CVSS 9.9
EPSS 0.00
CVE-2026-22683 HIGH
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
Apr 07, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-64011 MEDIUM
Nextcloud Server 30.0.0 - Authenticated Insecure Direct Object Reference via /core/preview fileId Parameter
Dec 12, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-66558 LOW
Nextcloud Twofactor WebAuthn <1.4.2, <2.4.1 - Info Disclosure
Dec 05, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-66557 MEDIUM
Nextcloud Deck <1.14.6-1.15.2 - Privilege Escalation
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-66556 LOW
Nextcloud talk <20.1.8-21.1.2 - Info Disclosure
Dec 05, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-66554 LOW
Nextcloud <5.5.4, <6.0.6, <7.2.5 - Info Disclosure
Dec 05, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-66553 MEDIUM
Nextcloud Tables <0.8.7 & 0.9.4 - Info Disclosure
Dec 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-66551 MEDIUM
Nextcloud Tables <0.8.6-0.9.3 - Privilege Escalation
Dec 05, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-66549 LOW
Nextcloud Desktop <3.16.5 - Info Disclosure
Dec 05, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-66548 LOW
Nextcloud Deck <1.12.7, 1.14.4, 1.15.1 - Info Disclosure
Dec 05, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-66545 LOW
Nextcloud <14.0.11, <15.3.12, <16.0.15, <17.0.14, <18.1.8, <19.1.8,...
Dec 05, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-66515 LOW
Nextcloud Approval <1.3.1, 2.5.0 - Privilege Escalation
Dec 05, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-66514 LOW
Nextcloud Mail < 5.5.3 - Authenticated Stored HTML Injection in Message List
Dec 05, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-66513 MEDIUM
Nextcloud Tables <0.8.9, <0.9.6, <1.0.1 - Info Disclosure
Dec 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-66552 MEDIUM
Nextcloud Server <30.0.9-31.0.1 - Info Disclosure
Dec 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-66550 MEDIUM
Nextcloud Calendar <4.7.17-5.2.4 - Info Disclosure
Dec 05, 2025
CVSS 5.7
EPSS 0.00
CVE-2025-66547 MEDIUM
Nextcloud Server <31.0.1 - Info Disclosure
Dec 05, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-66546 LOW
Nextcloud Calendar <4.7.19, 5.5.6, 6.0.1 - Info Disclosure
Dec 05, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-66512 MEDIUM
Nextcloud Server <31.0.12-32.0.3 - Info Disclosure
Dec 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-66511 MEDIUM
Nextcloud Calendar <6.0.3 - Info Disclosure
Dec 05, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-66510 MEDIUM
Nextcloud Server <32.0.1 - Info Disclosure
Dec 05, 2025
CVSS 4.5
EPSS 0.00
CVE-2025-59788 MEDIUM
Nextcloud < 32.0.1 - Cross-Site Scripting via Crafted PDF File
Dec 04, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-58051 MEDIUM
Nextcloud Tables <0.7.6, 0.8.8, 0.9.5 - Info Disclosure
Oct 16, 2025
CVSS 6.5
EPSS 0.00