Vulnerabilities > Nextcloud > Nextcloud Server > Low

DATE CVE VULNERABILITY TITLE RISK
2021-02-03 CVE-2020-8294 Cross-site Scripting vulnerability in Nextcloud Server
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
network
nextcloud CWE-79
3.5
2020-11-16 CVE-2020-8152 Insufficiently Protected Credentials vulnerability in Nextcloud Server
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.
local
low complexity
nextcloud CWE-522
2.1
2020-11-09 CVE-2020-8150 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
1.9
2020-11-02 CVE-2020-8173 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
network
nextcloud CWE-311
3.5
2020-02-04 CVE-2019-15612 Session Fixation vulnerability in Nextcloud Server
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
local
low complexity
nextcloud CWE-384
3.2
2020-02-04 CVE-2019-15618 Cross-site Scripting vulnerability in Nextcloud Server
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
network
nextcloud CWE-79
3.5
2020-02-04 CVE-2019-15619 Cross-site Scripting vulnerability in Nextcloud Deck and Nextcloud Server
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
network
nextcloud CWE-79
3.5
2019-07-30 CVE-2019-5451 Missing Authentication for Critical Function vulnerability in Nextcloud Server
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
local
low complexity
nextcloud CWE-306
2.1
2018-10-30 CVE-2018-16463 Session Fixation vulnerability in Nextcloud Server
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
network
high complexity
nextcloud CWE-384
3.6
2018-10-30 CVE-2018-16464 Improper Authentication vulnerability in Nextcloud Server
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
network
nextcloud CWE-287
3.5