cbcvebase.

Nextcloud Desktop vulnerabilities

27 known vulnerabilities affecting nextcloud/desktop.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM17LOW1

Vulnerabilities

Page 2 of 2
CVE-2022-39332P4MEDIUMCVSS 5.4fixed in 3.6.12022-11-25
CVE-2022-39332 [MEDIUM] CWE-79 CVE-2022-39332: Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperTex Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
nvd
CVE-2022-39331P4MEDIUMCVSS 5.4fixed in 3.6.12022-11-25
CVE-2022-39331 [MEDIUM] CWE-79 CVE-2022-39331: Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperTex Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
nvd
CVE-2020-8189P4MEDIUMCVSS 5.4fixed in 2.6.52020-08-21
CVE-2020-8189 [MEDIUM] CWE-79 CVE-2020-8189: A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (includin A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
nvd
CVE-2020-8230P4MEDIUMCVSS 5.5fixed in 2.6.52020-08-17
CVE-2020-8230 [MEDIUM] CWE-119 CVE-2020-8230: A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and D A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
nvd
CVE-2022-39334P4MEDIUMCVSS 4.7fixed in 3.6.12022-11-25
CVE-2022-39334 [MEDIUM] CWE-295 CVE-2022-39334: Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripti Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes sensitive data or credentials to a network attacker. This affects the CLI only.
nvd
CVE-2020-8229P4MEDIUMCVSS 5.5fixed in 2.6.52020-08-10
CVE-2020-8229 [MEDIUM] CWE-400 CVE-2020-8229: A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS aga A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
nvd
CVE-2025-66549P4LOWCVSS 2.7≥ 3.0.0, < 3.16.52025-12-05
CVE-2025-66549 [LOW] CWE-209 CVE-2025-66549: Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
nvd
Nextcloud Desktop vulnerabilities | cvebase