Nextcloud Server
Vendor:
First CVE: Sep 17, 2016 · Active for 9 years
190
Total CVEs
More Total CVEs than 99% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nextcloud Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2016
9 years ago
Most Recent CVE
Jun 1, 2026
53 days ago
CVE Severity & Scoring
Nextcloud Server190 CVEs
66%
23%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (4.7%)
Network178 (93.7%)
Unknown0 (0.0%)
Physical3 (1.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low178 (93.7%)
High12 (6.3%)
Unknown0 (0.0%)
User Interaction
None143 (75.3%)
Unknown0 (0.0%)
Required47 (24.7%)
Privileges Required
Low103 (54.2%)
High16 (8.4%)
None71 (37.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (190 CVEs).
190 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26482HIGH Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only availa | Mar 30, 2023 | 8.8 | 42 | NO | YES |
CVE-2026-45281HIGH Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other user | Jun 1, 2026 | 8.1 | 33 | NO | NO |
CVE-2021-32802CRITICAL Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud serv | Sep 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-32726CRITICAL Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. | Jul 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-45810MEDIUM Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation a | Jun 1, 2026 | 6.8 | 29 | NO | NO |
CVE-2021-22915CRITICAL Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potential | Jun 11, 2021 | 9.8 | 29 | NO | NO |
CVE-2026-45285MEDIUM Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud | Jun 1, 2026 | 6.4 | 28 | NO | NO |
CVE-2021-32688HIGH Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to b | Jul 12, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-32679HIGH Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `D | Jul 12, 2021 | 8.8 | 28 | NO | NO |
CVE-2018-3775HIGH Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. | Aug 12, 2018 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (190 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (190 CVEs).
Media Mentions
Signals from CVEs in this product scope (190 CVEs).
Top CNAs Publishing CVEs For Nextcloud Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 30.0.0 | 1 | 4.3 | 0.2% | 0 | 0 |
| 29.0.0 | 1 | 3.5 | 0.4% | 0 | 0 |
| 27.0.0 | 8 | 6.3 | 0.6% | 0 | 0 |
| 26.0.0 | 1 | 6.7 | 0.2% | 0 | 0 |
| 25.0.0 | 4 | 6.0 | 0.7% | 0 | 0 |
| 24.0.2 | 1 | 5.3 | 0.5% | 0 | 0 |
| 24.0.0 | 1 | 3.5 | 2.5% | 0 | 0 |
| 23.0.0 | 1 | 6.5 | 1.6% | 0 | 0 |
| 22.2.0 | 2 | 4.8 | 1.0% | 0 | 0 |
| 19.0.1 | 1 | 5.3 | 0.7% | 0 | 0 |
| 19.0.0 | 1 | 6.5 | 1.5% | 0 | 0 |
| 16.0.1 | 1 | 6.1 | 0.9% | 0 | 0 |
| 14.0.0 | 2 | 5.6 | 0.8% | 0 | 0 |
| 12.0.5 | 1 | 5.7 | 0.8% | 0 | 0 |
| 10.0.2 | 2 | 5.3 | 1.1% | 0 | 0 |
| 10.0 | 1 | 4.3 | 1.6% | 0 | 0 |