ownCloud Guests before 0.12.5 contains an unauthenticated user enumeration vulnerability caused by insufficient validation of the token in showPasswordForm at /apps/guests/register/{email}/{token}, letting unauthenticated attackers enumerate valid guest users, exploit requires no authentication.
id: CVE-2025-59716
info:
name: ownCloud Guests - User Enumeration
author: DhiyaneshDk
severit
...