Contacts
This hub aggregates every CVE we track for Contacts, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM7LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
1
0
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Contacts.
- CVE-2025-13167Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated user...5.4
- CVE-2025-66554Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field3.5
- CVE-2021-25524Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.4.0
- CVE-2021-39221XSS in Contacts6.4
- CVE-2020-8280A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.5.4
- CVE-2020-8281A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.5.4
- CVE-2020-8181A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.4.3
- CVE-2018-3764In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected ...4.8
Product normalization is registry-driven with AI assist and human review. How it works