deck vulnerabilities
CVEs whose affected-version data names the deck package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-77170Medium· 4.3The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
▾ SunlitNextcloud · DeckEPSS 0.27%via NVD
CVE-2025-66557Medium· 5.4Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permissi…
▾ Sunlitnextcloud · deckEPSS 0.28%via NVD