Vulnerabilities > Nextcloud > Nextcloud Server > Low

DATE CVE VULNERABILITY TITLE RISK
2020-11-09 CVE-2020-8150 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
1.9
2020-11-02 CVE-2020-8173 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
network
nextcloud CWE-311
3.5
2020-02-04 CVE-2019-15612 Session Fixation vulnerability in Nextcloud Server
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
local
low complexity
nextcloud CWE-384
3.2
2020-02-04 CVE-2019-15618 Cross-site Scripting vulnerability in Nextcloud Server
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
network
nextcloud CWE-79
3.5
2020-02-04 CVE-2019-15619 Cross-site Scripting vulnerability in Nextcloud Deck and Nextcloud Server
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
network
nextcloud CWE-79
3.5
2019-07-30 CVE-2019-5451 Missing Authentication for Critical Function vulnerability in Nextcloud Server
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
local
low complexity
nextcloud CWE-306
2.1
2018-10-30 CVE-2018-16463 Session Fixation vulnerability in Nextcloud Server
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
network
high complexity
nextcloud CWE-384
3.6
2018-10-30 CVE-2018-16464 Improper Authentication vulnerability in Nextcloud Server
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
network
nextcloud CWE-287
3.5
2018-08-13 CVE-2018-3780 Cross-site Scripting vulnerability in Nextcloud Server
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction.
network
nextcloud CWE-79
3.5
2017-05-08 CVE-2017-0890 Cross-site Scripting vulnerability in Nextcloud Server
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module.
network
nextcloud CWE-79
3.5