CVE-2025-66513

Severity
5.3MEDIUM
EPSS
0.0%
top 93.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5

Description

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDnextcloud/tables0.6.00.8.9+2
CVEListV5nextcloud/security-advisories< 0.8.9+2

Patches

🔴Vulnerability Details

1
CVEList
Nextcloud Tables app share information not limited to relevant users2025-12-05