Nextcloud
Nextcloud Calendar: vulnerabilidades y CVE
Nextcloud Calendar tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45286 | Media (4.3) | 0.46% | — | 1 jun 2026 | Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the… |
| CVE-2025-66550 | Media (5.7) | 0.34% | — | 5 dic 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud… |
| CVE-2025-66546 | Baja (3.3) | 0.14% | — | 5 dic 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is… |
| CVE-2025-66511 | Media (6.5) | 0.29% | — | 5 dic 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens,… |
| CVE-2024-37316 | Media (4.6) | 0.36% | — | 14 jun 2024 | Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the… |
| CVE-2023-48308 | Media (6.5) | 0.55% | — | 22 dic 2023 | Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the… |
| CVE-2023-45150 | Media (4.3) | 0.39% | — | 16 oct 2023 | Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were… |
| CVE-2023-33183 | Media (4.3) | 0.44% | — | 30 may 2023 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is… |
| CVE-2022-24838 | Crítica (9.8) | 33% | — | 11 abr 2022 | Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON… |
| CVE-2018-3763 | Media (4.8) | 0.61% | — | 5 jul 2018 | In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names,… |