---
id: CVE-2025-53828
title: >-
  SharePoint for ownCloud is an application for using SharePoint with the file
  storage, synchronization, and sharing application ownCloud Classic
summary: >-
  SharePoint for ownCloud is an application for using SharePoint with the file
  storage, synchronization, and sharing application ownCloud Classic. In
  SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud
  10 prior to…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-918
published: '2026-07-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T15:10:00.560'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53828'
references:
  - url: >-
      https://github.com/owncloud/security-advisories/security/advisories/GHSA-4m66-rpfj-m5f6
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00393
epssPercentile: 0.31011
ingestedAt: '2026-09-30T16:10:06.740Z'
---

## Overview

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
