Security: nextcloud/security-advisories
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Calendar app used predictable proposal participant tokensGHSA-whm3-vv55-gf27 published
Dec 5, 2025 by nickvergessenModerate -
XSS in SVG images when opened outside of NextcloudGHSA-qcw2-p26m-9gc5 published
Dec 5, 2025 by nickvergessenModerate -
Mail stored HTML injection in subject textGHSA-v394-8gpc-6fv5 published
Dec 5, 2025 by nickvergessenLow -
Tables app share information not limited to relevant usersGHSA-2cwj-qp49-4xfw published
Dec 5, 2025 by nickvergessenModerate -
Contacts search allowed users to retrieve contact information of other users beyond their contact listGHSA-495w-cqv6-wr59 published
Dec 5, 2025 by nickvergessenModerate -
Users with read-only permissions for team folder can restore deleted files from trash binGHSA-2vrq-fhmf-c49m published
Dec 5, 2025 by nickvergessenLow -
Approval app allows users to request approval for other users fileGHSA-q26g-fmjq-x5g5 published
Dec 5, 2025 by nickvergessenLow -
Calendar app allowed booking appointments without the generated tokenGHSA-7x2j-2674-fj95 published
Dec 5, 2025 by nickvergessenLow -
Users can modify tags on files that do not belong to themGHSA-hq6c-r898-fgf2 published
Dec 5, 2025 by nickvergessenModerate -
Deck app allows to spoof file extensions by using RTLO charactersGHSA-xjvq-xvr7-xpg6 published
Dec 5, 2025 by nickvergessenLow