CVE-2025-66551Medium· 6.3▾ SunlitNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.
tables >= 0.4.0, < 0.8.6tables >= 0.9.0, < 0.9.3Upgrade past the affected range:
tables 0.9.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68493Low· 3.1After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
CVE-2026-45810Medium· 6.8Nextcloud is an open source content collaboration platform
CVE-2026-45722High· 7.1Nextcloud is an open source content collaboration platform
CVE-2026-45545High· 8.2Nextcloud is an open source content collaboration platform
CVE-2026-45544Medium· 4.3Nextcloud is an open source content collaboration platform
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.