CVE Tools

Nextcloud

339 CVEs tracked since 2016. Since Sep 2016, none of them reached CISA KEV.

Nextcloud CVEs per month

Sep 2016 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nextcloud CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0910
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03100
2017-04null or fewer
2017-0560
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0740
2018-0840
2018-09null or fewer
2018-1050
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-0770
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02210
2020-0330
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-0850
2020-09null or fewer
2020-1070
2020-1160
2020-12null or fewer
2021-0140
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06170
2021-07150
2021-08null or fewer
2021-0990
2021-1080
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-0360
2022-0460
2022-0560
2022-06null or fewer
2022-07null or fewer
2022-0850
2022-0960
2022-1030
2022-1190
2022-1240
2023-0150
2023-02120
2023-03null or fewer
2023-0490
2023-0570
2023-0660
2023-07null or fewer
2023-08100
2023-09null or fewer
2023-1060
2023-1180
2023-1240
2024-0170
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06120
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11170
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-0550
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12210
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06260
2026-07null or fewer
2026-08null or fewer
2026-0970

Products

The products that kept showing up in Nextcloud's monthly top three, with their CVEs summed over those months.

  1. Security-advisories23927 months
  2. Nextcloud Server16235 months
  3. Nextcloud207 months
  4. Desktop154 months
  5. Deck84 months
  6. Mail74 months
  7. Talk64 months
  8. Nextcloud Enterprise Server52 months
  9. Server52 months
  10. Tables52 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Nextcloud.

  1. CVE-2026-77166The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.2.4
  2. CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.6.5
  3. CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this re...6.2
  4. CVE-2026-77169A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization ...6.5
  5. CVE-2026-77170The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.4.3
  6. CVE-2026-82985The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration...6.5
  7. CVE-2026-82982The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after t...4.3
  8. CVE-2026-82980Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that...6.3
  9. CVE-2026-68493After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.3.1
  10. CVE-2026-45810Nextcloud: Propfind requests for file comments allowed to load comments for other files6.8
  11. CVE-2026-45722Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views7.1
  12. CVE-2026-45691Nextcloud: Bypass of second factor authentication on DAV endpoints5.9
  13. CVE-2026-45690Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay5.9
  14. CVE-2026-45545Nextcloud: SQL Injection in Column Type Parameter Allows Arbitrary SQL Execution8.2
  15. CVE-2026-45544Nextcloud: Information Disclosure of view filter metdata via Broken Sensitive Data Masking in ViewService4.3

The record

Peak rank
#23 in Feb 2020
Busiest month shown
Jun 2026, 26 CVEs
Months with a KEV entry
0 since Sep 2016
Monthly snapshots
41 since 2016
Nextcloud's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store