Talk
Vendor:
First CVE: Aug 13, 2018 · Active for 7 years
20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Talk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2018
7 years ago
Most Recent CVE
Dec 5, 2025
231 days ago
CVE Severity & Scoring
Talk20 CVEs
20%
70%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (10.0%)
Network16 (80.0%)
Unknown0 (0.0%)
Physical2 (10.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (55.0%)
Unknown0 (0.0%)
Required9 (45.0%)
Privileges Required
Low9 (45.0%)
High2 (10.0%)
None9 (45.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8180CRITICAL A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator. | Jun 8, 2020 | 9.9 | 30 | NO | NO |
CVE-2023-39957HIGH Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps t | Aug 10, 2023 | 7.8 | 22 | NO | NO |
CVE-2021-41180MEDIUM Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due | Mar 8, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-32689MEDIUM Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get | Jul 12, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-41926MEDIUM Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malici | Nov 25, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-24887MEDIUM Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in c | Apr 27, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-39222MEDIUM Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation | Nov 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-32676MEDIUM Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate th | Jun 16, 2021 | 6.5 | 21 | NO | NO |
CVE-2022-39212MEDIUM Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who | Sep 17, 2022 | 5.3 | 20 | NO | NO |
CVE-2018-3781MEDIUM A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only aff | Aug 13, 2018 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Talk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 17.0.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 14.0.0 | 1 | 4.3 | 0.9% | 0 | 0 |
| 13.0.0 | 1 | 6.1 | 0.9% | 0 | 0 |