Owncloud develops a modestly represented but widely deployed self-hosted file-synchronization and collaboration platform that spans server, desktop client, and ancillary security components. The vendor's vulnerability portfolio concentrates on input-handling and session-management weaknesses, with cross-site scripting, cross-site request forgery, and information-disclosure flaws as the recurring attack surfaces across its server and client products. These weakness classes reflect the web-application and data-access patterns characteristic of file-sharing and collaborative software. Defenders should prioritize patching instances in internet-facing deployments and review access controls around sensitive data exposure; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owncloud over time
Signals from CVEs in this vendor scope (168 CVEs).
168 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49103HIGH An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL | Nov 21, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-49105CRITICAL An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, an | Nov 21, 2023 | 9.8 | 48 | NO | YES |
CVE-2015-4716HIGH Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the | Oct 21, 2015 | 10.0 | 36 | NO | NO |
CVE-2014-2044HIGH Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upl | Oct 6, 2014 | 7.5 | 34 | NO | YES |
CVE-2025-59716MEDIUM ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied tok | Nov 5, 2025 | 5.3 | 32 | NO | YES |
CVE-2021-35946CRITICAL A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions. | Sep 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2014-1665MEDIUM Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file. | Mar 20, 2018 | 5.4 | 29 | NO | YES |
CVE-2012-2270MEDIUM Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks | Apr 20, 2012 | 5.8 | 29 | NO | YES |
CVE-2021-33828HIGH The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be | Jan 15, 2022 | 8.8 | 28 | NO | NO |
CVE-2014-2052CRITICAL Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other | Feb 11, 2020 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (168 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owncloud.
Media articles that mention a CVE ID that affects a product developed by Owncloud — matched by CVE ID, not by vendor name.