Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

NextCloud — Vulnerabilities & Security Advisories 261

Browse all 261 CVE security advisories affecting NextCloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-39952 Advanced permissions not respected when copying entire group folders — security-advisoriesCWE-284 6.5 Medium2023-08-10
CVE-2023-35928 Nextcloud user scoped external storage can be used to gather credentials of other users — security-advisoriesCWE-274 8.5 High2023-06-23
CVE-2023-35927 Nextcloud system addressbooks can be modified by malicious trusted server — security-advisoriesCWE-284 7.6 High2023-06-23
CVE-2023-35173 End-to-End encrypted file-drops can be made inaccessible — security-advisoriesCWE-284 5.7 Medium2023-06-23
CVE-2023-35172 Nextcloud Server password reset endpoint is not brute force protected — security-advisoriesCWE-307 8.7 High2023-06-23
CVE-2023-35171 Nextcloud Server vulnerable to open redirect on "Unsupported browser" warning — security-advisoriesCWE-601 4.1 Medium2023-06-23
CVE-2023-32320 Nextcloud Server's brute force protection allows someone to send more requests than intended — security-advisoriesCWE-307 8.7 High2023-06-22
CVE-2023-33183 Error in calendar when booking an appointment reveals the full path of the website — security-advisoriesCWE-285 2.6 Low2023-05-30
CVE-2023-33182 Nextcloud Contacts photos only sanitized if mime type is all lower case — security-advisoriesCWE-20--2023-05-30
CVE-2023-33184 Blind SSRF in the Nextcloud Mail app on avatar endpoint — security-advisoriesCWE-918 3.5 Low2023-05-27
CVE-2023-32319 Basic auth header on WebDAV requests is not brute-force protected in Nextcloud — security-advisoriesCWE-307 8.1 High2023-05-26
CVE-2023-31128 NextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command Injection — cookbookCWE-78 8.1 High2023-05-26
CVE-2023-32318 User session not correctly destroyed on logout — security-advisoriesCWE-613 7.2 High2023-05-26
CVE-2023-32074 Nextcloud user_oidc app is missing brute force protection — security-advisoriesCWE-307 8.0 High2023-05-25
CVE-2023-28847 Nextcloud Server missing brute force protection for passwords of password protected share links — security-advisoriesCWE-307 3.1 Low2023-04-25
CVE-2023-30540 Chat poll data can still be queried from API after purging history in Nextcloud talk — security-advisoriesCWE-200 3.5 Low2023-04-17
CVE-2023-30539 Users can set up workflows using restricted and invisible system tags in Nextcloud — security-advisoriesCWE-284 6.5 Medium2023-04-17
CVE-2023-29000 Nextcloud Desktop client does not verify received singed certificate in end-to-end encryption — security-advisoriesCWE-295 5.4 Medium2023-04-04
CVE-2023-28999 Nextcloud: Lack of authenticity of metadata keys allows a malicious server to gain access to E2EE folders — security-advisoriesCWE-325 6.9 Medium2023-04-04
CVE-2023-28998 Nextcloud Desktop client misbehaves with E2EE when the server returns empty list of metadata keys — security-advisoriesCWE-325 6.7 Medium2023-04-04
CVE-2023-28997 Nextcloud Desktop: Initialization vector reuse in E2EE allows malicious server admin to break, manipulate, access files — security-advisoriesCWE-323 6.7 Medium2023-04-04
CVE-2023-28848 CSRF protection on user_oidc login returned the expected token in case of an error — security-advisoriesCWE-352 4.8 Medium2023-04-04
CVE-2023-28834 Full path of data directory exposed to Nextcloud server users — security-advisoriesCWE-212 3.5 Low2023-04-03
CVE-2023-28845 Chat room membership disclosed via autocompletion in Nextcloud talk — security-advisoriesCWE-284 3.5 Low2023-03-31
CVE-2023-28844 User without download rights can download older version of that file in nextcloud server — security-advisoriesCWE-284 5.7 Medium2023-03-31
CVE-2023-28645 Secure view can be bypassed by using internal API endpoint in Nextcloud richdocuments — security-advisoriesCWE-284 5.7 Medium2023-03-31
CVE-2023-28835 Insecure randomness for default password in nextcloud — security-advisoriesCWE-338 3.5 Low2023-03-30
CVE-2023-28833 Unrestricted filenames for logo or favicon as admin in the theming settings in nextcloud server — security-advisoriesCWE-22 2.4 Low2023-03-30
CVE-2023-28644 Reference fetch can saturate the server bandwidth for 10 seconds in nextcloud server — security-advisoriesCWE-400 5.7 Medium2023-03-30
CVE-2023-28643 Potential share collision for recipients when caching is enabled in nextcloud server — security-advisoriesCWE-706 5.5 Medium2023-03-30

This page lists every published CVE security advisory associated with NextCloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.