Versions
< 12.2.8
>= 25.0.0, < 25.0.4
<= 3.6.1
< 20.0.14.4
>= 25.0.1, < 25.0.7
>= 14.0.0, < 14.0.6
>= 24.0.0, < 24.0.12.5
< 1.3.5
< 1.1.1
>= 21.0.0, < 21.0.9.13
>= 22.0.0, < 22.2.10.15
>= 5.2.0, < 5.2.5
>= 3.0.0, < 3.3.0
>= 25.0.0, < 25.0.2
>= 3.0.0, < 3.7.0
>= 15.0.0, < 15.0.5
>= 4.0.0, < 4.2.3
>= 1.15.0, < 1.15.4
>= 3.7.0, < 3.7.2
>= 23.0.0, < 23.0.12.8
< 13.0.5
>= 3.0.0, < 3.14.2
>= 21.0.0, < 21.0.4
>= 24.0.0, < 24.0.12.4
Nextcloud Enterprise Server >= 25.0.0, < 25.0.7
>= 24.0.0, < 24.0.12.9
>= 1.9.0, < 1.9.6
< 1.9.6
>= 28.0.0, < 28.0.11
>= 29.0.0, < 29.0.9
< 12.2.2
< 22.2.0
20.0.13
Nextcloud Server >= 25.0.0, < 25.0.4
>= 1.8.0, < 1.8.7
>= 6.0.0, < 6.3.1
< 22.2.6
< 2.2.5
>= 3.0.0, < 3.0.1
Nextcloud Enterprise Server >= 23.0.0.0, < 23.0.12.7
>= 1.5.5, < 1.8.2
Nextcloud Files automated tagging:>= 1.14.0, < 1.14.2
< 23.0.12
>= 26.0.0, < 26.0.9
>= 26.0.0, < 26.0.2
< 3.8.7
>= 27.0.0, < 28.0.6
>= 20.0.0, < 20.0.14.15
< 22.2.7
>= 2.0.0, < 2.1.2
>= 1.9.0, < 1.14.6
< 1.8.2
< 1.2.1
>= 24.0.0, < 24.0.3
>= 1.8.0, < 1.8.2
< 11.2.2
< 1.15.0
Nextcloud Files automated tagging:>= 1.13.0, < 1.13.1
>= 27.0.0, < 27.1.9
>= 5.0.0, < 5.1.5
< 3.19.1
>= 25.0.0, < 25.0.9
>= 23.0.0, < 23.0.12.9
< 21.0.8
< 1.4.8
>= 10.0.0, < 10.0.8
>= 11.0.0, < 11.2.2
>= 29.0.0, < 29.0.7
>= 23.0.0, < 23.0.12.11
Nextcloud Server >= 26.0.0, < 26.0.2
>= 14.0.0, < 14.0.3
< 3.8.6,
>= 3.0.5, < 4.8.0
>= 1.2.0, < 1.2.1
>= 23.0.0, < 23.0.7
< 23.0.1
Nextcloud Files automated tagging:>= 1.15.0, < 1.15.3
< 3.19.0
>= 11.1.0, < 11.1.2
>= 23.0.0, < 23.0.6
>= 20.0.0, < 20.0.14.16
>= 1.5.0, < 1.5.3
>= 0.20.0, < 0.20.11
>= 5.0.0, < 5.0.4
>= 5.0.0, < 5.0.3
>= 3.7.0, < 3.24.1
>= 2.0.0, < 2.2.2
>= 24.0.0, < 24.0.8
>= 1.6.0, < 1.6.6
>= 27.0.0, < 27.1.10
< 12.1.2
>= 24.0.0, < 24.0.12.8
= 1.6.0
< 4.2.3
>= 1.0.0, < 1.3.3
Nextcloud Files automated tagging:>= 1.16.0, < 1.16.1
< 24.0.9
< 22.2.9
>= 26.0.0, < 26.0.1
>= 1.7.0, < 1.7.3
>= 25.0.2, < 25.0.6
< 23.0.10
< 9.0.10
>= 19.0.0, < 19.0.13.10
< 4.9.2
>= 4.1.0, < 4.2.4
>= 27.0.0, < 27.1.7
< 3.2.2
< 3.6.3
Nextcloud Enterprise Server >= 21.0.0.0, < 21.0.9.12
>= 14.0.0, < 14.0.9
Nextcloud Enterprise Server >= 21.0.0, < 21.0.9.10
< 14.1.0
>= 3.0.0, < 3.8.0
< 3.5.5
< 11.2.0
Nextcloud Enterprise Server >= 20.0.0.0, < 20.0.14.14
>= 24.0.4, < 24.0.12.5
Nextcloud Enterprise Server >= 26.0.0, < 26.0.2
>= 2.0.0, < 2.2.1
= 7.0.0
< 23.0.7
< 12.3.0
>= 22.0.0, < 22.2.10.13
>= 1.10.0, < 1.11.2
>= 25.0.0, < 25.0.8
>= 26.0.0, < 26.0.3
>= 1.5.0, < 1.5.6
< 22.2.8
>= 20.0.0, < 20.0.10
< 22.2.4
< 10.0.7
>= 26.0.0, < 26.0.8
>= 26.0.0, < 26.0.4
>= 24.0.0, < 24.0.7
>= 14.0.0, < 14.0.4
>= 0.6.0, < 0.8.0
>= 28.0.0, < 28.0.10
>= 3.1.0, < 3.3.0
>= 22.0.0, < 22.2.1
>= 25.0.0, < 25.0.11
>= 25.0.0, < 25.0.13.4
>= 28.0.0, < 28.0.4
>= 1.3.0, < 1.4.1
Nextcloud Enterprise Server >= 25.0.0, < 25.0.4
< 23.0.2
>= 24.0.0, < 24.0.1
< 17.0.0
>= 4.3.0, < 4.6.8
< 4.7.0
= 25.0.0
>= 16.0.0, < 16.0.6
>= 27.0.0, < 27.1.8
< 15.0.3
>= 1.9.0, < 1.9.5
>= 27.0.0, < 29.0.1
>= 29.0.0, < 29.0.8
>= 4.7.0, < 4.7.2
>= 1.5.0, < 1.5.4
>= 4.6.0, < 4.9.3
>= 3.1.0, < 3.6.3
< 1.11.8
>= 1.13.0, < 1.13.6
>= 20.0.0, < 20.0.11
>= 21.0.0, < 21.0.2
>= 24.0.0, < 24.0.9
Nextcloud Server >= 24.0.0, < 24.0.10
>= 30.0.0, < 30.0.2
< 3.3.0
>= 0.21.0, < 0.21.4
>= 2.4.0, < 2.4.5
< 23.0.9
>= 23.0.0, < 23.0.3
>= 28.0.0, < 28.0.5
< 1.10.4, < 1.11.0
>= 4.0.0, < 4.2.1
>= 26.0.0, < 26.0.13
>= 27.0.0, < 27.1.0
>= 1.4.0, < 1.4.6
Nextcloud Enterprise Server >= 21.0.0, < 21.0.9.12
< 3.17.1
>= 2.0.0, < 2.2.8
Nextcloud Server >= 25.0.0, < 25.0.7
>= 23.0.0, < 23.0.5
>= 27.0.0, < 27.0.1
>= 22.0.0, < 22.2.4
>= 1.11.0, < 1.12.1
>= 3.0.0, < 4.5.3
< 20.0.14
>= 23.0.0, < 23.0.12.12
>= 26.0.0, < 26.0.12
< 0.19.1
>= 1.4.0, < 1.4.5
>= 3.6.0, < 3.6.2
>= 1.5.0, < 1.5.1
>= 30.0.0, < 30.0.1
>= 1.0.0, < 1.3.0
>= 24.0.0, < 24.0.11
< 1.2.11
>= 4.0.0, < 4.2.9
>= 15.0.0, < 15.0.8
< 3.8.3
Nextcloud Enterprise Server >= 19.0.0, < 19.0.13.9
>= 2.5.0, < 2.5.1
>= 22.0.0, < 22.1.0
< 22.2.10
>= 1.6.0, < 1.6.5
>= 28.0.0, < 28.0.12
>= 7.0.0, < 7.0.2
>= 24.0.0, < 24.0.5
>= 25.0.0, < 25.0.1
>= 22.2.0, < 22.2.1
< 15.0.2
>= 21.0.0, < 21.0.3
>= 29.0.0, < 29.0.5
>= 21.0.0, < 21.0.6
= 3.6.0
< 1.4.3
>= 26.0.0, < 26.0.6
>= 23.0.0, < 23.0.4
>= 24.0.4, < 24.0.7
< 24.0.7
>= 2.1.0, < 2.2.11
>= 1.0.0, < 4.4.4
< 3.8.4
>=2.2.0, < 2.2.10
>= 3.0.3 , <= 3.2.4
>= 4.4.0, < 4.8.0
>= 1.7.0, < 1.7.5
>= 1.13.0, < 2.2.8
Nextcloud Enterprise Server >= 24.0.0.0, < 24.0.12.2
>= 24.0.0, < 24.0.4
< 4.2.6
>= 12.0.0.alpha-1, < 12.0.0
>= 0.20.0, < 0.20.10
< 4.0.3
< 13.0.0
Nextcloud Enterprise Server >= 22.0.0.0, < 22.2.10.12
>= 29.0.0, < 29.0.1
< 6.3.2
>= 12.2.0, < 12.2.7
Nextcloud Enterprise Server >= 22.0.0, < 22.2.10.12
>= 23.0.0, < 23.0.9
>= 21.0.0, < 21.0.5
Nextcloud Server:>= 25.0.0, < 25.0.5
< 23.0.8
>= 10.1.0, < 10.1.4
>= 2.2.0, < 2.3.4
>= 1.12.0, < 1.12.9
>= 27.0.0, < 27.1.3
Nextcloud Enterprise Server >= 24.0.0, < 24.0.12.2
>= 15.0.0, < 15.0.4
>= 6.0.0, < 6.1.0
< 3.21.0
< 3.02
>= 22.0.0, < 22.2.10.16
>= 3.0.0, < 3.6.5
>= 22.0.0, < 22.0.1
Nextcloud Enterprise Server >= 23.0.0, < 23.0.12.7
>= 23.0.0, < 23.0.1
< 13.0.8
>= 3.7.0, < 3.7.7
>= 1.14.0, < 1.14.1
>= 24.0.0, < 24.0.12.7
>= 1.12.0, < 1.12.4
< 1.12.8
>= 28.0.0, < 28.0.9
>= 23.0.0, < 23.0.12.13
< 20.0.13
>= 24.0.4, < 24.0.8
< 24.0.10
>= 23.0.0, < 23.0.12.6
>= 0.21.0, < 0.21.3
Nextcloud Server:< 24.0.11
>= 13.0.0, < 13.0.7
Nextcloud Files automated tagging:>= 1.11.0, < 1.11.1
< 28.0.0
< 1.12.2
< 1.2.9
< 20.0.12
<= 1.3.6
>= 28.0.0, < 28.0.6
>= 0.3.0, < 0.8.1
>= 1.10.0, < 1.11.3
< 2.2.2
< 23.0.11
< 1.3.2
< 3.6.1
< 11.3.4
>= 25.0.0, < 25.0.5
>= 2.4.0, < 2.4.1
< 19.0.11
< 3.15.1
>= 23.0.0, < 23.0.14
Nextcloud Enterprise Server >= 24.0.0, < 24.0.10
>= 13.0.0, < 13.0.10
>= 6.0.0, < 6.0.1
< 3.16.1
Nextcloud Enterprise Server >= 22.0.0, < 22.2.10.10
>= 25.0.0, < 25.0.13
Nextcloud Files automated tagging:>= 1.12.0, < 1.12.1
>= 3.13.0, < 3.25.0
< 22.2.10.5
>= 24.0.0, < 24.0.10
>= 4.0.0, < 4.2.0
>= 1.13.0, < 1.14.5
>= 17.0.0, < 17.1.1
>= 25.0.0, < 25.0.3
>= 1.60, < 1.6.5
>= 1.3.0, < 1.4.4
< 3.12.0
>= 6.0.0, < 6.3.2
>= 22.0.0, < 22.2.10.14
>= 1.13.0, < 1.13.1
>= 24.0.0, < 24.0.2
>= 1.1.0, < 1.4.1
< 1.15.3
>= 5.0.0, < 5.0.10
< 1.12.1
Nextcloud Enterprise Server >= 23.0.0, < 23.0.12.5
< 19.0.13
>= 27.0.0, < 27.1.4
< 0.19.15
>= 28.0.0, < 28.0.3
Recent CVEs
CVE-2024-52509
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients. It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2.
CVE-2024-52508
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like [email protected] that does not support auto configuration, and an attacker managed to register autoconfig.tld, the used email details would be send to the server of the attacker. It is recommended that the Nextcloud Mail app is upgraded to 1.14.6, 1.15.4, 2.2.11, 3.6.3, 3.7.7 or 4.0.0.
CVE-2024-52510
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that the Nextcloud Desktop client is upgraded to 3.14.2 or later.
CVE-2024-52507
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
CVE-2024-52511
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
CVE-2024-52512
user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0.
CVE-2024-52513
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.
CVE-2024-52514
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access the blocked files depending on the user access control rules. It is recommended that the Nextcloud Server is upgraded to 27.1.9, 28.0.5 or 29.0.0 and Nextcloud Enterprise Server is upgraded to 21.0.9.18, 22.2.10.23, 23.0.12.18, 24.0.12.14, 25.0.13.9, 26.0.13.3, 27.1.9, 28.0.5 or 29.0.0.
CVE-2024-52517
Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.
CVE-2024-37887
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.