Nextcloud Tables vulnerabilities
8 known vulnerabilities affecting nextcloud/tables.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2026-45545P3HIGHCVSS 8.2≥ 0.7.0, < 0.7.7≥ 0.8.0, < 0.8.10+2 more2026-06-01
CVE-2026-45545 [HIGH] CWE-89 CVE-2026-45545: Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it i
nvd
CVE-2026-45722P3HIGHCVSS 7.1≥ 0.9.0, < 0.9.7≥ 1.0.0, < 1.0.22026-06-01
CVE-2026-45722 [HIGH] CWE-89 CVE-2026-45722: Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extractin
nvd
CVE-2024-52511P4MEDIUMCVSS 6.5≥ 0.6.0, < 0.8.02024-11-15
CVE-2024-52511 [MEDIUM] CWE-639 CVE-2024-52511: Nextcloud Tables allows users to to create tables with individual columns. By directly specifying th
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
nvd
CVE-2025-66513P4MEDIUMCVSS 5.3≥ 0.6.0, < 0.8.9≥ 0.9.0, < 0.9.6+1 more2025-12-05
CVE-2025-66513 [MEDIUM] CWE-639 CVE-2025-66513: Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.
nvd
CVE-2025-66553P4MEDIUMCVSS 4.3≥ 0.8.0, < 0.8.7≥ 0.9.0, < 0.9.42025-12-05
CVE-2025-66553 [MEDIUM] CWE-639 CVE-2025-66553: Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.
nvd
CVE-2026-45544P4MEDIUMCVSS 4.3≥ 0.8.0, < 1.0.42026-06-01
CVE-2026-45544 [MEDIUM] CWE-1230 CVE-2026-45544: Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.
nvd
CVE-2025-66551P4MEDIUMCVSS 4.3≥ 0.4.0, < 0.8.6≥ 0.9.0, < 0.9.32025-12-05
CVE-2025-66551 [MEDIUM] CWE-639 CVE-2025-66551: Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.
nvd
CVE-2024-52507P4MEDIUMCVSS 4.3≥ 0.3.0, < 0.8.12024-11-15
CVE-2024-52507 [MEDIUM] CWE-639 CVE-2024-52507: Nextcloud Tables allows users to to create tables with individual columns. The information which Tab
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
nvd