Vulnerabilities > Owncloud > Owncloud > 10.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-02-09 CVE-2020-28645 Improper Input Validation vulnerability in Owncloud
Deleting users with certain names caused system files to be deleted.
network
low complexity
owncloud CWE-20
5.0
2021-02-09 CVE-2020-28644 Cross-Site Request Forgery (CSRF) vulnerability in Owncloud
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints.
network
owncloud CWE-352
4.3
2021-01-15 CVE-2020-16255 Cross-site Scripting vulnerability in Owncloud
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
network
owncloud CWE-79
4.3
2017-07-17 CVE-2017-9340 Unspecified vulnerability in Owncloud
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.
network
low complexity
owncloud
4.0
2017-07-17 CVE-2017-9339 Unspecified vulnerability in Owncloud
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars.
network
low complexity
owncloud
5.0
2017-07-17 CVE-2017-9338 Cross-site Scripting vulnerability in Owncloud
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2.
network
owncloud CWE-79
3.5
2017-07-17 CVE-2017-8896 Cross-site Scripting vulnerability in Owncloud
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.
network
owncloud CWE-79
4.3