« Back to list

Nextcloud

Nextcloud Server: vulnerabilities and CVEs

Nextcloud Server has 191 published vulnerabilities, 16 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.

CVEs191
Last 12 months16
Critical7
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-45810Medium (6.8)0.44%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access…
CVE-2026-45691Medium (5.9)0.43%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password…
CVE-2026-45690Medium (5.9)0.43%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge…
CVE-2026-45285Medium (6.4)0.49%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member…
CVE-2026-45283Medium (4.3)0.36%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files…
CVE-2026-45282Medium (6.5)0.48%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when…
CVE-2026-45281High (8.1)0.50%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could…
CVE-2026-45279Medium (6.5)0.57%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin…
CVE-2026-45157Medium (6.3)0.39%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could…
CVE-2026-45155Low (2.6)0.31%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by…
CVE-2025-64011Medium (4.3)0.27%—Dec 12, 2025
Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating…
CVE-2025-66552Medium (4.3)0.31%—Dec 5, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all…
CVE-2025-66547Medium (4.3)0.28%—Dec 5, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This…
CVE-2025-66512Medium (6.1)0.28%—Dec 5, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy…
CVE-2025-66510Medium (4.9)0.36%—Dec 5, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to…
CVE-2025-59788Medium (5.4)0.30%—Dec 4, 2025
Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8,…
CVE-2025-47794Medium (4.3)0.47%—May 16, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1,…
CVE-2025-47793Medium (6.5)0.79%—May 16, 2025
Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and…
CVE-2025-47791Medium (5.3)0.36%—May 16, 2025
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to…
CVE-2025-47790Medium (6.4)0.38%—May 16, 2025
Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have…
CVE-2024-52514Low (3.5)0.48%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder…
CVE-2024-52513Medium (4.3)0.53%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without…
CVE-2024-52525High (7.5)0.34%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session…
CVE-2024-52523Medium (6.5)0.64%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to…
CVE-2024-52521Medium (5.3)0.40%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as…
CVE-2024-52520Medium (6.5)0.79%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is…
CVE-2024-52519High (8.2)0.50%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would…
CVE-2024-52518Medium (5.4)0.54%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to…
CVE-2024-52517Medium (5.9)0.60%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker…
CVE-2024-52516Medium (4.3)0.43%—Nov 15, 2024
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Nextcloud