Owncloud Server
Vendor:
First CVE: Apr 20, 2012 · Active for 14 years
108
Total CVEs
More Total CVEs than 99% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Owncloud Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2012
14 years ago
Most Recent CVE
Nov 21, 2023
976 days ago
CVE Severity & Scoring
Owncloud Server108 CVEs
12%
73%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (10.2%)
Unknown96 (88.9%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low11 (10.2%)
High1 (0.9%)
Unknown96 (88.9%)
User Interaction
None8 (7.4%)
Unknown96 (88.9%)
Required4 (3.7%)
Privileges Required
Low6 (5.6%)
High1 (0.9%)
None5 (4.6%)
Unknown96 (88.9%)
Top CVEs
Signals from CVEs in this product scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49105CRITICAL An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, an | Nov 21, 2023 | 9.8 | 48 | NO | YES |
CVE-2015-4716HIGH Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the | Oct 21, 2015 | 10.0 | 36 | NO | NO |
CVE-2014-2044HIGH Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upl | Oct 6, 2014 | 7.5 | 34 | NO | YES |
CVE-2012-2270MEDIUM Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks | Apr 20, 2012 | 5.8 | 29 | NO | YES |
CVE-2014-2052CRITICAL Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other | Feb 11, 2020 | 9.8 | 28 | NO | NO |
CVE-2015-4717HIGH The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, w | Oct 21, 2015 | 7.8 | 25 | NO | NO |
CVE-2014-2054HIGH PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read ar | Jun 4, 2014 | 7.5 | 25 | NO | NO |
CVE-2014-2053HIGH getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have | Jun 4, 2014 | 7.5 | 25 | NO | NO |
CVE-2014-4929MEDIUM Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local fi | Aug 20, 2014 | 6.8 | 24 | NO | NO |
CVE-2014-2051HIGH ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query." | Jun 5, 2014 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (108 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.9% of CVEs· 96th percentile
ExploitDB
3 CVEs
2.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (108 CVEs).
Media Mentions
Signals from CVEs in this product scope (108 CVEs).
Top CNAs Publishing CVEs For Owncloud Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1.4 | 3 | 5.9 | 1.8% | 0 | 0 |
| 8.1.3 | 4 | 5.5 | 1.8% | 0 | 0 |
| 8.1.1 | 4 | 5.5 | 1.8% | 0 | 0 |
| 8.1.0 | 7 | 6.1 | 2.2% | 0 | 0 |
| 8.0.9 | 2 | 4.6 | 1.0% | 0 | 0 |
| 8.0.8 | 2 | 4.6 | 1.0% | 0 | 0 |
| 8.0.6 | 2 | 4.6 | 1.0% | 0 | 0 |
| 8.0.5 | 5 | 5.9 | 2.0% | 0 | 0 |
| 8.0.4 | 6 | 5.6 | 1.9% | 0 | 0 |
| 8.0.3 | 10 | 6.4 | 4.3% | 0 | 0 |
| 8.0.2 | 10 | 6.4 | 4.3% | 0 | 0 |
| 8.0.0 | 10 | 6.4 | 4.3% | 0 | 0 |
| 7.0.7 | 3 | 6.8 | 2.7% | 0 | 0 |
| 7.0.6 | 4 | 6.1 | 2.3% | 0 | 0 |
| 7.0.5 | 6 | 6.9 | 2.5% | 0 | 0 |
| 7.0.4 | 6 | 6.9 | 2.5% | 0 | 0 |
| 7.0.3 | 6 | 6.9 | 2.5% | 0 | 0 |
| 7.0.2 | 14 | 5.7 | 1.8% | 0 | 0 |
| 7.0.1 | 14 | 5.7 | 1.8% | 0 | 0 |
| 7.0.0 | 14 | 5.7 | 1.8% | 0 | 0 |