Nextcloud Server vulnerabilities
181 known vulnerabilities affecting nextcloud/nextcloud_server.
Total CVEs
181
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH41MEDIUM118LOW15
Vulnerabilities
Page 2 of 10
CVE-2024-52514LOWCVSS 3.5≥ 21.0.0, < 21.0.9.18≥ 22.0.0, < 22.2.10.23+6 more2024-11-15
CVE-2024-52514 [MEDIUM] CWE-284 CVE-2024-52514: Nextcloud Server is a self hosted personal cloud system. After a user received a share with some fil
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access the blocked files depending on the user access control rules. It is recom
nvd
CVE-2024-37882HIGHCVSS 8.1≥ 26.0.0, < 26.0.13≥ 27.0.0, < 27.1.8+4 more2024-06-14
CVE-2024-37882 [HIGH] CWE-284 CVE-2024-37882: Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share perm
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.
nvd
CVE-2024-37313HIGHCVSS 7.5≥ 21.0.0, < 21.0.9.17≥ 22.0.0, < 22.2.10.22+6 more2024-06-14
CVE-2024-37313 [HIGH] CWE-287 CVE-2024-37313: Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0
nvd
CVE-2024-37315MEDIUMCVSS 4.3≥ 23.0.0, ≤ 23.0.12≥ 24.0.0, ≤ 24.0.12+4 more2024-06-14
CVE-2024-37315 [LOW] CWE-284 CVE-2024-37315: Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file
Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12,
nvd
CVE-2024-37884MEDIUMCVSS 5.4≥ 25.0.0, < 25.0.13.7≥ 26.0.0, < 26.0.13+2 more2024-06-14
CVE-2024-37884 [LOW] CWE-284 CVE-2024-37884: Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete re
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.
nvd
CVE-2024-37314LOWCVSS 3.5≥ 25.0.0, < 25.0.7≥ 26.0.0, < 26.0.22024-06-14
CVE-2024-37314 [LOW] CWE-284 CVE-2024-37314: Nextcloud Photos is a photo management app. Users can remove photos from the album of registered use
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
nvd
CVE-2024-37887LOWCVSS 3.5≥ 27.0.0, < 27.1.10≥ 28.0.0, ≤ 28.0.6+2 more2024-06-14
CVE-2024-37887 [LOW] CWE-284 CVE-2024-37887: Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.
nvd
CVE-2024-22403LOWCVSS 3.7fixed in 28.0.02024-01-18
CVE-2024-22403 [LOW] CWE-613 CVE-2024-22403: Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not ex
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10 minutes and will no longer be authenticated. To exploit this vulnerability an a
nvd
CVE-2023-49792CRITICALCVSS 9.8≥ 23.0.0, < 23.0.12.13≥ 24.0.0, < 24.0.12.9+3 more2023-12-22
CVE-2023-49792 [MEDIUM] CWE-307 CVE-2023-49792: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Se
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trusted proxy the server could be tricked into reading a w
nvd
CVE-2023-49791MEDIUMCVSS 5.4≥ 23.0.0, < 23.0.12.13≥ 24.0.0, < 24.0.12.9+3 more2023-12-22
CVE-2023-49791 [MEDIUM] CWE-284 CVE-2023-49791: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Se
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages to get access to an active session of another user via another way, they
nvd
CVE-2023-48306CRITICALCVSS 9.8≥ 22.0.0, < 22.2.10.16≥ 23.0.0, < 23.0.12.11+4 more2023-11-21
CVE-2023-48306 [MEDIUM] CWE-918 CVE-2023-48306: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Enterprise Server, the DNS pin middlewar
nvd
CVE-2023-48239HIGHCVSS 7.1≥ 20.0.0, < 20.0.14.16≥ 21.0.0, < 21.0.9.13+6 more2023-11-21
CVE-2023-48239 [HIGH] CWE-284 CVE-2023-48239: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and starting in version 20.0.0 and prior to versions 20.0.14.16, 21.0.9.13, 22.2.10.15, 23.0.12.12, 24.0.12.8, 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Enterprise Server,
nvd
CVE-2023-48305MEDIUMCVSS 4.4≥ 25.0.0, < 25.0.11≥ 26.0.0, < 26.0.6+1 more2023-11-21
CVE-2023-48305 [MEDIUM] CWE-312 CVE-2023-48305: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, when the log level was set to debug, the user_ldap app logged user passwords in plaintext into the log file. If the log file was then le
nvd
CVE-2023-48302MEDIUMCVSS 5.4≥ 25.0.0, < 25.0.13≥ 26.0.0, < 26.0.8+1 more2023-11-21
CVE-2023-48302 [LOW] CWE-79 CVE-2023-48302: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, when a user is tricked into copy pasting HTML code without markup (Ctrl+Shift+V) the markup will actually render. Nextcloud Server and Nextc
nvd
CVE-2023-48301MEDIUMCVSS 5.4≥ 25.0.0, ≤ 25.0.13≥ 25.0.0, < 25.0.13+4 more2023-11-21
CVE-2023-48301 [LOW] CWE-79 CVE-2023-48301: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, an attacker could insert links into circles name that would be opened when clicking the circle name in a search filter. Nextcloud Server and
nvd
CVE-2023-48304MEDIUMCVSS 4.3≥ 22.0.0, ≤ 22.2.10.16≥ 23.0.0, < 23.0.12.11+4 more2023-11-21
CVE-2023-48304 [MEDIUM] CWE-639 CVE-2023-48304: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Enterprise Server, an attacker could ena
nvd
CVE-2023-48303LOWCVSS 2.7≥ 25.0.0, < 25.0.11≥ 26.0.0, < 26.0.6+1 more2023-11-21
CVE-2023-48303 [LOW] CWE-284 CVE-2023-48303: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in ver
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, admins can change authentication details of user configured external storage. Nextcloud Server and Nextcloud Enterprise Server versions 25.
nvd
CVE-2023-45151HIGHCVSS 8.8≥ 25.0.0, < 25.0.8≥ 26.0.0, < 26.0.3+1 more2023-10-16
CVE-2023-45151 [MEDIUM] CWE-312 CVE-2023-45151: Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2
Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended to upgrade their Nextcloud Server to version 25.0.8, 26.0.3 or 27.0.1. Th
nvd
CVE-2023-45148MEDIUMCVSS 4.3≥ 22.0.0, < 22.2.10.16≥ 23.0.0, < 23.0.12.11+4 more2023-10-16
CVE-2023-45148 [MEDIUM] CWE-307 CVE-2023-45148: Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the
Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade to versions 25.0.11, 26.0.6 or 27.1.0. Users unable to upgrade should change their config setting `memcache.distr
nvd
CVE-2023-39960HIGHCVSS 7.5≥ 22.0.0, < 22.2.10.14≥ 23.0.0, < 23.0.12.9+3 more2023-10-13
CVE-2023-39960 [MEDIUM] CWE-307 CVE-2023-39960: Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Se
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud Enterprise Server starting with 22.0.0 and prior to 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, and 26.0.4; missing protection allows an attacker to brute force passwords on th
nvd