Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Owncloud

First CVE: Apr 20, 2012Active for: 14 yearsTotal CVEs: 168
46.3
VTI Score
High

Owncloud develops a modestly represented but widely deployed self-hosted file-synchronization and collaboration platform that spans server, desktop client, and ancillary security components. The vendor's vulnerability portfolio concentrates on input-handling and session-management weaknesses, with cross-site scripting, cross-site request forgery, and information-disclosure flaws as the recurring attack surfaces across its server and client products. These weakness classes reflect the web-application and data-access patterns characteristic of file-sharing and collaborative software. Defenders should prioritize patching instances in internet-facing deployments and review access controls around sensitive data exposure; current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
168
Total CVEs
More Total CVEs than 100% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Owncloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2012
14 years ago
Most Recent CVE
Nov 5, 2025
261 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (168 CVEs).

168 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-49103HIGH
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL
Nov 21, 20237.597YESYES
CVE-2023-49105CRITICAL
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, an
Nov 21, 20239.848NOYES
CVE-2015-4716HIGH
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the
Oct 21, 201510.036NONO
CVE-2014-2044HIGH
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upl
Oct 6, 20147.534NOYES
CVE-2025-59716MEDIUM
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied tok
Nov 5, 20255.332NOYES
CVE-2021-35946CRITICAL
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.
Sep 7, 20219.831NONO
CVE-2014-1665MEDIUM
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Mar 20, 20185.429NOYES
CVE-2012-2270MEDIUM
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks
Apr 20, 20125.829NOYES
CVE-2021-33828HIGH
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be
Jan 15, 20228.828NONO
CVE-2014-2052CRITICAL
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other
Feb 11, 20209.828NONO
View all 168 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products168 CVEs
10%
72%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (3.6%)
Network51 (30.4%)
Unknown107 (63.7%)
Physical3 (1.8%)
Adjacent Network1 (0.6%)
Attack Complexity
Low56 (33.3%)
High5 (3.0%)
Unknown107 (63.7%)
User Interaction
None42 (25.0%)
Unknown107 (63.7%)
Required19 (11.3%)
Privileges Required
Low21 (12.5%)
High3 (1.8%)
None37 (22.0%)
Unknown107 (63.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (168 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 99th percentile
Metasploit
1 CVE
0.6% of CVEs· 97th percentile
Nuclei
3 CVEs
1.8% of CVEs· 95th percentile
ExploitDB
4 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Owncloud.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Owncloud — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Owncloud's Products

View all 4 CNAs →

Top CWEs