CVE Tools

Nextcloud Server

189 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nextcloud Server, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Nextcloud Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nextcloud Server CVEs per month
MonthCVEs
2024-100
2024-1111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-054
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-126
2026-010
2026-020
2026-030
2026-040
2026-050
2026-068
2026-070
2026-080
2026-090

Severity

How the 189 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical32%
  • High2815%
  • Medium11460%
  • Low4423%

Latest CVEs

The 15 most recently published vulnerabilities affecting Nextcloud Server.

  1. CVE-2026-45810Nextcloud: Propfind requests for file comments allowed to load comments for other files6.8
  2. CVE-2026-45691Nextcloud: Bypass of second factor authentication on DAV endpoints5.9
  3. CVE-2026-45690Nextcloud: Two-Factor Authentication Bypass via Pending Session Token Replay5.9
  4. CVE-2026-45285Nextcloud: Hidden Public Link creation when sharing to a Team External Member6.4
  5. CVE-2026-45283Nextcloud: Files Lock app allows users to lock and unlock files of other users6.3
  6. CVE-2026-45282Nextcloud: Logged-in user bypasses share password and download restrictions on Text attachments via documentId leads to unauthorized file access6.5
  7. CVE-2026-45281Nextcloud: Cross-Account Calendar Takeover via Unauthorized Group-Member-Set Update8.1
  8. CVE-2026-45279Nextcloud: Limited path traversal via template API if using `{lang}` in config4.4
  9. CVE-2025-64011Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any authenticated user can access previews of arbitrary files belonging to other u...4.3
  10. CVE-2025-66552Nextcloud Server admin_audit does not log all actions on files in groupfolders4.3
  11. CVE-2025-66547Nextcloud Server users can modify tags on files that do not belong to them4.3
  12. CVE-2025-66512Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud5.4
  13. CVE-2025-66510Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list4.5
  14. CVE-2025-59788Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 2...6.4
  15. CVE-2025-47794Nextcloud Server vulnerable to insecure temporary file creation, race with write access and permission2.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store