📦 Nextcloud Server

by Nextcloud

🔍 What is Nextcloud Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-26482

CRITICAL CVSS 9.0 Mar 30, 2023

This vulnerability in Nextcloud server allows non-admin users to create workflows that should be restricted to administrators. Since some workflows can execute scripts on the server, this can lead to ...

CVE-2021-32802

CRITICAL CVSS 9.3 Sep 7, 2021

Nextcloud servers with image previews enabled are vulnerable to server-side request forgery (SSRF), file disclosure, or potential remote code execution when processing malicious image files. This affe...

CVE-2021-22915

CRITICAL CVSS 9.8 Jun 11, 2021

This vulnerability allows attackers to bypass Nextcloud's brute-force protection by using IPv6 addresses, which weren't included in rate-limiting calculations. Attackers can perform unlimited authenti...

CVE-2024-37313

HIGH CVSS 7.3 Jun 14, 2024

This vulnerability allows attackers to bypass two-factor authentication (2FA) in Nextcloud Server after successfully obtaining valid user credentials. It affects self-hosted Nextcloud instances where ...

CVE-2023-48239

HIGH CVSS 8.5 Nov 21, 2023

This vulnerability in Nextcloud Server allows a malicious user to update any personal or global external storage configuration, making those storage locations inaccessible to all other users. It affec...

CVE-2023-39962

HIGH CVSS 7.7 Aug 10, 2023

This vulnerability in Nextcloud Server allows a malicious authenticated user to delete any personal or global external storage configuration, making those storage locations inaccessible to all users. ...

CVE-2023-35172

HIGH CVSS 8.7 Jun 23, 2023

This vulnerability allows attackers to brute-force password reset links in NextCloud Server and NextCloud Enterprise Server, potentially enabling unauthorized account access. Affected users include al...

CVE-2023-35927

HIGH CVSS 7.6 Jun 23, 2023

This vulnerability allows a malicious Nextcloud server to modify or delete VCards in the system addressbook on a trusted partner server. It affects Nextcloud Server and Enterprise Server installations...

CVE-2023-32320

HIGH CVSS 8.7 Jun 22, 2023

This vulnerability in Nextcloud Server allows attackers to bypass rate limiting protections by sending parallel requests, enabling brute-force attacks on protected details like passwords or tokens. It...

CVE-2023-32319

HIGH CVSS 8.1 May 26, 2023

This vulnerability allows attackers to brute-force user credentials on Nextcloud servers via WebDAV endpoints when basic authentication is used and the username is not an email address. It affects Nex...

CVE-2023-32318

HIGH CVSS 7.2 May 26, 2023

This CVE describes a session handling vulnerability in Nextcloud Server where logout doesn't properly destroy sessions if cookies aren't manually cleared. An attacker who authenticates with any accoun...

CVE-2021-32726

HIGH CVSS 7.1 Jul 12, 2021

This vulnerability in Nextcloud Server allows account takeover when usernames are reused. When a user account is deleted, their WebAuthn authentication tokens remain active. If a new user later regist...

CVE-2021-32688

HIGH CVSS 8.8 Jul 12, 2021

This vulnerability in Nextcloud Server allows application-specific authentication tokens to escalate their own permissions. Tokens configured with no filesystem access can grant themselves full filesy...

CVE-2025-64011

MEDIUM CVSS 4.3 Dec 12, 2025

Nextcloud Server 30.0.0 contains an Insecure Direct Object Reference (IDOR) vulnerability in the /core/preview endpoint. Authenticated users can access previews of other users' files by manipulating t...

CVE-2025-66547

MEDIUM CVSS 4.3 Dec 5, 2025

This vulnerability allows non-privileged Nextcloud users to modify tags on files they shouldn't have access to through bulk tagging operations. It affects Nextcloud Server and Enterprise Server instal...

CVE-2025-66552

MEDIUM CVSS 4.3 Dec 5, 2025

This vulnerability in Nextcloud Server causes the admin_audit app to fail to log actions on files and folders within groupfolders due to incorrect path handling. It affects Nextcloud Server and Enterp...

CVE-2025-66512

MEDIUM CVSS 5.4 Dec 5, 2025

This vulnerability allows malicious users to bypass Nextcloud's Content Security Policy (CSP) by tricking users into viewing specially crafted SVG files outside the Nextcloud web interface. This affec...

CVE-2025-66510

MEDIUM CVSS 4.5 Dec 5, 2025

This vulnerability in Nextcloud Server allows authenticated users to retrieve personal data (emails, names, identifiers) of other users through the contacts search feature without proper access contro...

CVE-2024-52514

MEDIUM CVSS 4.1 Nov 15, 2024

This Nextcloud vulnerability allows users who receive shared folders containing blocked files to copy the intermediate folder structure, potentially bypassing file access controls. It affects Nextclou...

CVE-2024-52520

MEDIUM CVSS 5.7 Nov 15, 2024

This vulnerability in Nextcloud Server allows attackers to trick the link reference provider into downloading larger websites than intended when processing HEAD requests to find open-graph data. This ...

CVE-2024-52523

MEDIUM CVSS 4.6 Nov 15, 2024

This vulnerability in Nextcloud Server exposes fixed credentials for external storage configurations through the API and frontend. An attacker with an active user session can read these credentials in...

CVE-2024-52517

MEDIUM CVSS 4.6 Nov 15, 2024

This vulnerability in Nextcloud Server exposes global credentials in plain text through the API response when an attacker has access to an active user session. It allows unauthorized reading of sensit...

CVE-2024-52515

MEDIUM CVSS 5.7 Nov 15, 2024

This vulnerability in Nextcloud Server allows a malicious user to upload a manipulated SVG file that references other file paths. If the referenced file exists, the SVG preview will display that other...