Nextcloud Server

Vendor:

First CVE: Sep 17, 2016 · Active for 9 years

190
Total CVEs
More Total CVEs than 99% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Nextcloud Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2016
9 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

CVE Severity & Scoring

Nextcloud Server190 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local9 (4.7%)
Network178 (93.7%)
Unknown0 (0.0%)
Physical3 (1.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low178 (93.7%)
High12 (6.3%)
Unknown0 (0.0%)
User Interaction
None143 (75.3%)
Unknown0 (0.0%)
Required47 (24.7%)
Privileges Required
Low103 (54.2%)
High16 (8.4%)
None71 (37.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (190 CVEs).

190 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only availa
Mar 30, 20238.842NOYES
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other user
Jun 1, 20268.133NONO
Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud serv
Sep 7, 20219.832NONO
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted.
Jul 12, 20219.830NONO
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation a
Jun 1, 20266.829NONO
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potential
Jun 11, 20219.829NONO
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud
Jun 1, 20266.428NONO
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to b
Jul 12, 20218.828NONO
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `D
Jul 12, 20218.828NONO
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
Aug 12, 20188.828NONO

Exploit Exposure

Signals from CVEs in this product scope (190 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (190 CVEs).

Media Mentions

Signals from CVEs in this product scope (190 CVEs).

Top CNAs Publishing CVEs For Nextcloud Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
30.0.014.30.2%00
29.0.013.50.4%00
27.0.086.30.6%00
26.0.016.70.2%00
25.0.046.00.7%00
24.0.215.30.5%00
24.0.013.52.5%00
23.0.016.51.6%00
22.2.024.81.0%00
19.0.115.30.7%00
19.0.016.51.5%00
16.0.116.10.9%00
14.0.025.60.8%00
12.0.515.70.8%00
10.0.225.31.1%00
10.014.31.6%00