Vulnerabilities > Owncloud > Owncloud > 9.1.8

DATE CVE VULNERABILITY TITLE RISK
2021-02-09 CVE-2020-28645 Improper Input Validation vulnerability in Owncloud
Deleting users with certain names caused system files to be deleted.
network
low complexity
owncloud CWE-20
5.0
2021-02-09 CVE-2020-28644 Cross-Site Request Forgery (CSRF) vulnerability in Owncloud
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints.
network
owncloud CWE-352
4.3
2021-01-15 CVE-2020-16255 Cross-site Scripting vulnerability in Owncloud
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
network
owncloud CWE-79
4.3
2017-07-17 CVE-2017-9340 Unspecified vulnerability in Owncloud
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.
network
low complexity
owncloud
4.0
2017-07-17 CVE-2017-9339 Unspecified vulnerability in Owncloud
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars.
network
low complexity
owncloud
5.0