owncloud
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting owncloud.
- CVE-2025-53831DrawIO for ownCloud 10 is vulnerable to Stored XSS8.2
- CVE-2025-53830Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)9.1
- CVE-2025-53829ownCloud 10 is vulnerable to Relative Path Traversal8.0
- CVE-2025-53828SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)8.5
- CVE-2025-53827ownCloud Core: Updater has an exposed dangerous method or function9.1
- CVE-2019-25337OwnCloud 8.1.8 - Username Disclosure9.8
- CVE-2025-59716ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswor...5.3
- CVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has ...9.8
- CVE-2023-49104An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently ...8.7
- CVE-2023-49103An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL i...KEV10.0
- CVE-2023-23948ownCloud Android app vulnerable to SQL Injection6.2
- CVE-2023-24804ownCloud Android app vulnerable to Path Traversal5.0
- CVE-2022-43679The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.4.2
- CVE-2022-31649ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.7.5
- CVE-2022-25339ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.5.5