Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | >= 32.0.0beta1, < 32.0.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-66551 | 6.3 MEDIUM | Nextcloud Tables is missing an ownership check which allows moving columns into tables of |
| CVE-2025-66550 | 5.7 MEDIUM | Nextcloud Calendar attachments of local files are offered to downloaded |
| CVE-2025-66512 | 5.4 MEDIUM | Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud |
| CVE-2025-66557 | 5.4 MEDIUM | Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other |
| CVE-2025-66511 | 4.8 MEDIUM | Nextcloud Calendar app used predictable proposal participant tokens |
| CVE-2025-66553 | 4.3 MEDIUM | Nextcloud Tables app allowed users to view columns metadata information of any table |
| CVE-2025-66547 | 4.3 MEDIUM | Nextcloud Server users can modify tags on files that do not belong to them |
| CVE-2025-66552 | 4.3 MEDIUM | Nextcloud Server admin_audit does not log all actions on files in groupfolders |
| CVE-2025-66513 | 4.3 MEDIUM | Nextcloud Tables app share information not limited to relevant users |
| CVE-2025-66514 | 3.5 LOW | Nextcloud Mail stored HTML injection in subject text |
| CVE-2025-66545 | 3.5 LOW | Nextcloud Groupfolders users with read-only permissions for team folder can restore delete |
| CVE-2025-66554 | 3.5 LOW | Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title fie |
| CVE-2025-66556 | 3.5 LOW | Nextcloud talk allows participants to blindly delete poll drafts of other users by ID |
| CVE-2025-66548 | 3.3 LOW | Nextcloud Deck app allows to spoof file extensions by using RTLO characters |
| CVE-2025-66546 | 3.3 LOW | Nextcloud Calendar app allowed booking appointments without the generated token |
| CVE-2025-66558 | 3.1 LOW | Nextcloud Twofactor WebAuthn app was updated based on public key |
| CVE-2025-66515 | 2.7 LOW | Nextcloud Approval app allows users to request approval for other users file |
| CVE-2025-66549 | 2.4 LOW | Nextcloud Desktop discloses information when attempting to lock a file inside a end-to-end |
No comments yet