Nextcloud is a widely deployed self-hosted file synchronization, collaboration, and communication platform that serves as a privacy-conscious alternative to commercial cloud services, with a footprint spanning server, desktop, and mobile deployments. The vendor's vulnerability profile concentrates on access-control weaknesses, authentication flaws, and web-application issues such as cross-site scripting and sensitive-information exposure, reflecting the authentication and input-handling demands of a multi-user collaboration platform. While the product maintains a modest portfolio, its prominence in the landscape stems from its direct exposure to user authentication, file access policies, and web interfaces across organizations deploying on-premise and hybrid cloud deployments. Defenders should monitor this vendor's releases for authentication and access-control patches and integrate them into both server and client update cycles; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextcloud over time
Signals from CVEs in this vendor scope (373 CVEs).
373 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24838CRITICAL Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sani | Apr 11, 2022 | 9.8 | 48 | NO | NO |
CVE-2023-26482HIGH Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only availa | Mar 30, 2023 | 8.8 | 42 | NO | YES |
CVE-2026-45545HIGH Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authen | Jun 1, 2026 | 8.2 | 34 | NO | NO |
CVE-2020-8227MEDIUM Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory. | Aug 21, 2020 | 6.8 | 34 | NO | NO |
CVE-2026-45284HIGH Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authent | Jun 1, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-45281HIGH Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other user | Jun 1, 2026 | 8.1 | 33 | NO | NO |
CVE-2021-32802CRITICAL Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud serv | Sep 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-22683HIGH Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modificati | Apr 7, 2026 | 8.8 | 30 | NO | NO |
CVE-2023-32074CRITICAL user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgrade | May 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-32726CRITICAL Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. | Jul 12, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (373 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextcloud.
Media articles that mention a CVE ID that affects a product developed by Nextcloud — matched by CVE ID, not by vendor name.