Nextcloud
Nextcloud Server: vulnerabilities and CVEs
Nextcloud Server has 191 published vulnerabilities, 16 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs191
Last 12 months16
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45810 | Medium (6.8) | 0.44% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access… |
| CVE-2026-45691 | Medium (5.9) | 0.43% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password… |
| CVE-2026-45690 | Medium (5.9) | 0.43% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge… |
| CVE-2026-45285 | Medium (6.4) | 0.49% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member… |
| CVE-2026-45283 | Medium (4.3) | 0.36% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files… |
| CVE-2026-45282 | Medium (6.5) | 0.48% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when… |
| CVE-2026-45281 | High (8.1) | 0.50% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could… |
| CVE-2026-45279 | Medium (6.5) | 0.57% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin… |
| CVE-2026-45157 | Medium (6.3) | 0.39% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could… |
| CVE-2026-45155 | Low (2.6) | 0.31% | — | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by… |
| CVE-2025-64011 | Medium (4.3) | 0.27% | — | Dec 12, 2025 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other users by manipulating… |
| CVE-2025-66552 | Medium (4.3) | 0.31% | — | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all… |
| CVE-2025-66547 | Medium (4.3) | 0.28% | — | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This… |
| CVE-2025-66512 | Medium (6.1) | 0.28% | — | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy… |
| CVE-2025-66510 | Medium (4.9) | 0.36% | — | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to… |
| CVE-2025-59788 | Medium (5.4) | 0.30% | — | Dec 4, 2025 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8,… |
| CVE-2025-47794 | Medium (4.3) | 0.47% | — | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1,… |
| CVE-2025-47793 | Medium (6.5) | 0.79% | — | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and… |
| CVE-2025-47791 | Medium (5.3) | 0.36% | — | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to… |
| CVE-2025-47790 | Medium (6.4) | 0.38% | — | May 16, 2025 | Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have… |
| CVE-2024-52514 | Low (3.5) | 0.48% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder… |
| CVE-2024-52513 | Medium (4.3) | 0.53% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without… |
| CVE-2024-52525 | High (7.5) | 0.34% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session… |
| CVE-2024-52523 | Medium (6.5) | 0.64% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to… |
| CVE-2024-52521 | Medium (5.3) | 0.40% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as… |
| CVE-2024-52520 | Medium (6.5) | 0.79% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is… |
| CVE-2024-52519 | High (8.2) | 0.50% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would… |
| CVE-2024-52518 | Medium (5.4) | 0.54% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to… |
| CVE-2024-52517 | Medium (5.9) | 0.60% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker… |
| CVE-2024-52516 | Medium (4.3) | 0.43% | — | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.