Nextcloud Security Vulnerabilities (CVEs)

Track 53 security vulnerabilities affecting Nextcloud products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

6 Critical
18 High
20 Medium
9 Low
🔔 Get Alerts for Nextcloud
CVE-2025-64011 4.3

Nextcloud Server 30.0.0 contains an Insecure Direct Object Reference (IDOR) vulnerability in the /core/preview endpoint. Authenticated users can acces...

Dec 12, 2025
CVE-2025-66558 3.1

A vulnerability in Nextcloud's Twofactor WebAuthn plugin allows attackers to remove a user's WebAuthn 2FA device by correctly guessing a long random s...

Dec 5, 2025
CVE-2025-66549 2.4

Nextcloud Desktop client versions before 3.16.5 send file paths unencrypted to the server when manually locking files in end-to-end encrypted director...

Dec 5, 2025
CVE-2025-66551 6.3

This vulnerability in Nextcloud Tables allows authenticated malicious users to move columns they created into other users' tables without authorizatio...

Dec 5, 2025
CVE-2025-66553 4.3

CVE-2025-66553 is an authorization bypass vulnerability in Nextcloud Tables where authenticated users can view metadata of columns in other tables by ...

Dec 5, 2025
CVE-2025-66554 3.5

This vulnerability allows authenticated malicious users to inject CSS files by modifying their organization and title fields in the Nextcloud Contacts...

Dec 5, 2025
CVE-2025-66556 3.5

This vulnerability in Nextcloud Talk allows participants with chat permissions to delete poll drafts created by other participants within the same con...

Dec 5, 2025
CVE-2025-66557 5.4

This vulnerability in Nextcloud Deck allows users with 'Can share' permission to modify permissions of other recipients, potentially escalating privil...

Dec 5, 2025
CVE-2025-66513 4.3

Nextcloud Tables had an authorization bypass vulnerability where unprivileged users could view which tables were shared with which groups/users and th...

Dec 5, 2025
CVE-2025-66514 3.5

This vulnerability allows authenticated Nextcloud Mail users to inject HTML into email subject lines displayed in the message list. While JavaScript e...

Dec 5, 2025
CVE-2025-66515 2.7

This vulnerability in Nextcloud Approval app allows authenticated users listed as requesters in workflows to mark other users' files as 'pending appro...

Dec 5, 2025
CVE-2025-66545 3.5

This vulnerability in Nextcloud Groupfolders allows users with read-only permissions to restore files from the trash bin, bypassing intended access co...

Dec 5, 2025
CVE-2025-66548 3.3

This vulnerability in Nextcloud Deck allows attackers to spoof file extensions using Right-to-Left Override (RTLO) characters, tricking users into dow...

Dec 5, 2025
CVE-2025-66546 3.3

This vulnerability in Nextcloud Calendar allows attackers to blindly book appointments using sequential IDs without needing the appointment token. It ...

Dec 5, 2025
CVE-2025-66547 4.3

This vulnerability allows non-privileged Nextcloud users to modify tags on files they shouldn't have access to through bulk tagging operations. It aff...

Dec 5, 2025
CVE-2025-66550 5.7

This vulnerability in Nextcloud Calendar allows a malicious user to create calendar events with crafted attachments that automatically download files ...

Dec 5, 2025
CVE-2025-66552 4.3

This vulnerability in Nextcloud Server causes the admin_audit app to fail to log actions on files and folders within groupfolders due to incorrect pat...

Dec 5, 2025
CVE-2025-66510 4.5

This vulnerability in Nextcloud Server allows authenticated users to retrieve personal data (emails, names, identifiers) of other users through the co...

Dec 5, 2025
CVE-2025-66511 4.8

Nextcloud Calendar versions before 6.0.3 generate participant tokens for meeting proposals using a predictable hash function instead of cryptographica...

Dec 5, 2025
CVE-2025-66512 5.4

This vulnerability allows malicious users to bypass Nextcloud's Content Security Policy (CSP) by tricking users into viewing specially crafted SVG fil...

Dec 5, 2025
CVE-2024-52514 4.1

This Nextcloud vulnerability allows users who receive shared folders containing blocked files to copy the intermediate folder structure, potentially b...

Nov 15, 2024
CVE-2024-52508 8.2

This vulnerability in Nextcloud Mail allows email account setup details to be sent to attacker-controlled servers when auto-configuration fails. Attac...

Nov 15, 2024
CVE-2024-52510 4.2

The Nextcloud Desktop Client vulnerability allows attackers to bypass signature validation when a manipulated server sends an empty initial signature....

Nov 15, 2024
CVE-2024-52520 5.7

This vulnerability in Nextcloud Server allows attackers to trick the link reference provider into downloading larger websites than intended when proce...

Nov 15, 2024
CVE-2024-52523 4.6

This vulnerability in Nextcloud Server exposes fixed credentials for external storage configurations through the API and frontend. An attacker with an...

Nov 15, 2024
CVE-2024-52517 4.6

This vulnerability in Nextcloud Server exposes global credentials in plain text through the API response when an attacker has access to an active user...

Nov 15, 2024
CVE-2024-52515 5.7

This vulnerability in Nextcloud Server allows a malicious user to upload a manipulated SVG file that references other file paths. If the referenced fi...

Nov 15, 2024
CVE-2024-46958 9.1

This vulnerability in Nextcloud Desktop Client for Linux causes synchronized files to have overly permissive file permissions (world-writable or world...

Sep 16, 2024
CVE-2024-37883 4.3

This vulnerability in Nextcloud Deck allows users with access to a deck board to view comments and attachments from deleted cards, bypassing intended ...

Jun 14, 2024
CVE-2024-37886 5.4

CVE-2024-37886 is a signature verification bypass vulnerability in Nextcloud's user_oidc app that allows attackers to potentially forge OpenID Connect...

Jun 14, 2024
CVE-2024-37316 4.6

Authenticated users in Nextcloud Calendar can create events with manipulated attachment data that causes bad redirects for participants when clicked. ...

Jun 14, 2024
CVE-2024-37313 7.3

This vulnerability allows attackers to bypass two-factor authentication (2FA) in Nextcloud Server after successfully obtaining valid user credentials....

Jun 14, 2024
CVE-2024-30247 10.0

CVE-2024-30247 is a critical command injection vulnerability in NextCloudPi that allows unauthenticated attackers to execute arbitrary commands as roo...

Mar 29, 2024
CVE-2024-22212 9.6

CVE-2024-22212 is an authentication bypass vulnerability in Nextcloud Global Site Selector that allows attackers to authenticate as any user due to a ...

Jan 18, 2024
CVE-2023-48239 8.5

This vulnerability in Nextcloud Server allows a malicious user to update any personal or global external storage configuration, making those storage l...

Nov 21, 2023
CVE-2023-39962 7.7

This vulnerability in Nextcloud Server allows a malicious authenticated user to delete any personal or global external storage configuration, making t...

Aug 10, 2023
CVE-2023-35172 8.7

This vulnerability allows attackers to brute-force password reset links in NextCloud Server and NextCloud Enterprise Server, potentially enabling unau...

Jun 23, 2023
CVE-2023-35927 7.6

This vulnerability allows a malicious Nextcloud server to modify or delete VCards in the system addressbook on a trusted partner server. It affects Ne...

Jun 23, 2023
CVE-2023-32320 8.7

This vulnerability in Nextcloud Server allows attackers to bypass rate limiting protections by sending parallel requests, enabling brute-force attacks...

Jun 22, 2023
CVE-2023-32319 8.1

This vulnerability allows attackers to brute-force user credentials on Nextcloud servers via WebDAV endpoints when basic authentication is used and th...

May 26, 2023
CVE-2023-31128 8.1

This CVE describes a command injection vulnerability in NextCloud Cookbook's GitHub Actions workflow. Attackers with write access to the repository ca...

May 26, 2023
CVE-2023-32318 7.2

This CVE describes a session handling vulnerability in Nextcloud Server where logout doesn't properly destroy sessions if cookies aren't manually clea...

May 26, 2023
CVE-2023-26482 9.0

This vulnerability in Nextcloud server allows non-admin users to create workflows that should be restricted to administrators. Since some workflows ca...

Mar 30, 2023
CVE-2021-43863 7.5

This vulnerability in the Nextcloud Android app allows malicious apps on the same Android device to bypass permission controls and access Nextcloud us...

Jan 25, 2022
CVE-2021-39225 8.1

CVE-2021-39225 is an authorization bypass vulnerability in Nextcloud Deck that allows authenticated users to access other users' Deck cards without pr...

Oct 25, 2021
CVE-2021-41178 8.8

Nextcloud versions prior to 20.0.13, 21.0.5, and 22.2.0 contain a file traversal vulnerability that allows attackers to download arbitrary SVG files f...

Oct 25, 2021
CVE-2021-32802 9.3

Nextcloud servers with image previews enabled are vulnerable to server-side request forgery (SSRF), file disclosure, or potential remote code executio...

Sep 7, 2021
CVE-2021-37628 7.5

This vulnerability in Nextcloud Richdocuments allows attackers to bypass 'Upload Only' file drop restrictions and read arbitrary files from public lin...

Sep 7, 2021
CVE-2021-32726 7.1

This vulnerability in Nextcloud Server allows account takeover when usernames are reused. When a user account is deleted, their WebAuthn authenticatio...

Jul 12, 2021
CVE-2021-32689 8.1

This vulnerability in Nextcloud Talk allows user impersonation through username reuse, enabling unauthorized access to chat messages. Attackers who ca...

Jul 12, 2021

Why Monitor Nextcloud Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 53+ known vulnerabilities affecting Nextcloud products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Nextcloud packages in under 60 seconds. No agents required - completely agentless scanning that works across Nextcloud deployments.

Free vulnerability database: Access detailed information about every Nextcloud CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Nextcloud CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Nextcloud CVEs Free