nextcloud
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting nextcloud.
- CVE-2026-77166The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.2.4
- CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
- CVE-2026-77169A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization ...6.5
- CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2
- CVE-2026-77170The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.4.3
- CVE-2026-82982The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after t...4.3
- CVE-2026-82985The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration...6.5
- CVE-2026-82980Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that...6.3
- CVE-2026-68493After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.3.1
- CVE-2026-45810Nextcloud: Propfind requests for file comments allowed to load comments for other files6.8
- CVE-2026-45722Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views7.1
- CVE-2026-45691Nextcloud: Bypass of second factor authentication on DAV endpoints5.9
- CVE-2026-45690Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay5.9
- CVE-2026-45545Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution8.2
- CVE-2026-45544Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService4.3