Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nextcloud

First CVE: Sep 17, 2016Active for: 10 yearsTotal CVEs: 373
27.4
VTI Score
Low

Nextcloud is a widely deployed self-hosted file synchronization, collaboration, and communication platform that serves as a privacy-conscious alternative to commercial cloud services, with a footprint spanning server, desktop, and mobile deployments. The vendor's vulnerability profile concentrates on access-control weaknesses, authentication flaws, and web-application issues such as cross-site scripting and sensitive-information exposure, reflecting the authentication and input-handling demands of a multi-user collaboration platform. While the product maintains a modest portfolio, its prominence in the landscape stems from its direct exposure to user authentication, file access policies, and web interfaces across organizations deploying on-premise and hybrid cloud deployments. Defenders should monitor this vendor's releases for authentication and access-control patches and integrate them into both server and client update cycles; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
373
Total CVEs
More Total CVEs than 100% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nextcloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2016
9 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Products(39 total)

Top CVEs

Signals from CVEs in this vendor scope (373 CVEs).

373 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24838CRITICAL
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sani
Apr 11, 20229.848NONO
CVE-2023-26482HIGH
Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only availa
Mar 30, 20238.842NOYES
CVE-2026-45545HIGH
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authen
Jun 1, 20268.234NONO
CVE-2020-8227MEDIUM
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
Aug 21, 20206.834NONO
CVE-2026-45284HIGH
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authent
Jun 1, 20268.833NONO
CVE-2026-45281HIGH
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other user
Jun 1, 20268.133NONO
CVE-2021-32802CRITICAL
Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud serv
Sep 7, 20219.832NONO
CVE-2026-22683HIGH
Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modificati
Apr 7, 20268.830NONO
CVE-2023-32074CRITICAL
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgrade
May 25, 20239.830NONO
CVE-2021-32726CRITICAL
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted.
Jul 12, 20219.830NONO
View all 373 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products373 CVEs
9%
68%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local29 (7.8%)
Network326 (87.4%)
Unknown0 (0.0%)
Physical16 (4.3%)
Adjacent Network2 (0.5%)
Attack Complexity
Low355 (95.2%)
High18 (4.8%)
Unknown0 (0.0%)
User Interaction
None269 (72.1%)
Unknown0 (0.0%)
Required104 (27.9%)
Privileges Required
Low197 (52.8%)
High29 (7.8%)
None147 (39.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (373 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nextcloud.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nextcloud — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nextcloud's Products

View all 5 CNAs →

Top CWEs