VulnSea

Nextcloud has 19 CVEs on record. Cadence is steady at roughly 9 per quarter. The busiest recent month was June 2026 with 10. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-284 (5) and CWE-287 (3). Most affected products: Server (4), nextcloud_server (4), tables (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
9 prev 10

Products

  • Server 4
  • nextcloud_server 4
  • tables 3
  • Approval 1
  • Collectives 1
  • Deck 1
19
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Nextcloud vulnerabilities

CVEs affecting Nextcloud, newest first. Open any entry for full detail, references, and exploit status.

19 CVEsRSS

CVE-2026-77166Low· 2.4
today

The emoji field in the page emoji update endpoint does not properly validate user input

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

SunlitNextcloud · Collectivesvia NVD
CVE-2026-77165Medium· 6.5
today

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

SunlitNextcloud · Servervia NVD
CVE-2026-77169Medium· 6.5
3d ago

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables orga…

SunlitNextcloud · Team FoldersEPSS 0.24%via NVD
CVE-2026-68493Low· 3.1
3d ago

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

SunlitNextcloud · ServerEPSS 0.14%via NVD
CVE-2026-82982Medium· 4.3
3d ago

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforc…

SunlitNextcloud · ApprovalEPSS 0.19%via NVD
CVE-2026-77170Medium· 4.3
3d ago

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

SunlitNextcloud · DeckEPSS 0.15%via NVD
CVE-2026-82985Medium· 6.5
3d ago

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart alb…

SunlitNextcloud · ServerEPSS 0.20%via NVD
CVE-2026-82980Medium· 6.3
3d ago

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authentica…

SunlitNextcloud · Files LockEPSS 0.21%via NVD
CVE-2026-77164Medium· 6.2
3d ago

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

SunlitNextcloud · ServerEPSS 0.13%via NVD
CVE-2026-45810Medium· 6.8
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file commen…

Sunlitnextcloud · nextcloud_serverEPSS 0.25%via NVD
CVE-2026-45722High· 7.1
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL in…

Twilightnextcloud · tablesEPSS 0.30%via NVD
CVE-2026-45691Medium· 5.9
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOT…

Sunlitnextcloud · nextcloud_serverEPSS 0.29%via NVD
CVE-2026-45690Medium· 5.9
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's passw…

Sunlitnextcloud · nextcloud_serverEPSS 0.29%via NVD
CVE-2026-45545High· 8.2
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be abl…

Twilightnextcloud · tablesEPSS 0.32%via NVD
CVE-2026-45544Medium· 4.3
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions …

Sunlitnextcloud · tablesEPSS 0.22%via NVD
CVE-2026-45543Medium· 5.3
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to u…

Sunlitnextcloud · formsEPSS 0.27%via NVD
CVE-2026-45286Medium· 4.3
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint f…

Sunlitnextcloud · calendarEPSS 0.28%via NVD
CVE-2026-45285Medium· 6.4
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added vi…

Sunlitnextcloud · nextcloud_serverEPSS 0.29%via NVD
CVE-2026-45284Medium· 4.6
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This is…

Sunlitnextcloud · user_oidcEPSS 0.19%via NVD
Nextcloud vulnerabilities (CVEs) · VulnSea