Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3233342025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

debian логотип

CVE-2025-66512

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-66512

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-66510

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2025-66510

10 месяцев назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-88cv-g9gq-h6pq

10 месяцев назад

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-59788

10 месяцев назад

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewe ...

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2025-59788

10 месяцев назад

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-47794

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2025-47794

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2025-47793

больше 1 года назад

Nextcloud Server is a self hosted personal cloud system, and the Nextc ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-66512

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 5.4
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-66512

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-66510

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 4.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-66510

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.

CVSS3: 4.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-88cv-g9gq-h6pq

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-59788

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewe ...

CVSS3: 6.4
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-59788

Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-47794

Nextcloud Server is a self hosted personal cloud system. In Nextcloud ...

CVSS3: 2.6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-47794

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.

CVSS3: 2.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-47793

Nextcloud Server is a self hosted personal cloud system, and the Nextc ...

CVSS3: 4.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться