Vulnerabilities > Nextcloud > Nextcloud

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-5453 Improper Authentication vulnerability in Nextcloud
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
local
low complexity
nextcloud CWE-287
3.6
2019-07-30 CVE-2019-5452 Unspecified vulnerability in Nextcloud
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.
local
low complexity
nextcloud
2.1
2019-07-30 CVE-2019-5450 Cross-site Scripting vulnerability in Nextcloud
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.
local
low complexity
nextcloud CWE-79
4.6
2017-04-05 CVE-2017-0888 Improper Input Validation vulnerability in Nextcloud
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app.
network
low complexity
nextcloud CWE-20
4.3
2017-03-28 CVE-2016-9460 Improper Access Control vulnerability in multiple products
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app.
network
low complexity
nextcloud owncloud CWE-284
5.0