« Back to list

Nextcloud

Nextcloud Tables: vulnerabilities and CVEs

Nextcloud Tables has 10 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months8
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48067Medium (6.5)0.30%—Jun 22, 2026
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery()…
CVE-2026-45722High (7.1)0.49%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to…
CVE-2026-45545High (8.2)0.52%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the…
CVE-2026-45544Medium (4.3)0.37%—Jun 1, 2026
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been…
CVE-2025-66553Medium (4.3)0.28%—Dec 5, 2025
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the…
CVE-2025-66513Medium (5.3)0.29%—Dec 5, 2025
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective…
CVE-2025-66551Medium (4.3)0.25%—Dec 5, 2025
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability…
CVE-2025-58051Medium (6.5)0.53%—Oct 16, 2025
Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by…
CVE-2024-52511Medium (6.5)0.46%—Nov 15, 2024
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is…
CVE-2024-52507Medium (4.3)0.42%—Nov 15, 2024
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users.…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System2
  2. T1210 Exploitation of Remote Services2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Nextcloud