Owncloud Server

Vendor:

First CVE: Apr 20, 2012 · Active for 14 years

108
Total CVEs
More Total CVEs than 99% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Owncloud Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2012
14 years ago
Most Recent CVE
Nov 21, 2023
976 days ago

CVE Severity & Scoring

Owncloud Server108 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (10.2%)
Unknown96 (88.9%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low11 (10.2%)
High1 (0.9%)
Unknown96 (88.9%)
User Interaction
None8 (7.4%)
Unknown96 (88.9%)
Required4 (3.7%)
Privileges Required
Low6 (5.6%)
High1 (0.9%)
None5 (4.6%)
Unknown96 (88.9%)

Top CVEs

Signals from CVEs in this product scope (108 CVEs).

108 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, an
Nov 21, 20239.848NOYES
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the
Oct 21, 201510.036NONO
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upl
Oct 6, 20147.534NOYES
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks
Apr 20, 20125.829NOYES
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other
Feb 11, 20209.828NONO
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, w
Oct 21, 20157.825NONO
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read ar
Jun 4, 20147.525NONO
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have
Jun 4, 20147.525NONO
Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local fi
Aug 20, 20146.824NONO
ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."
Jun 5, 20147.524NONO

Exploit Exposure

Signals from CVEs in this product scope (108 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.9% of CVEs· 96th percentile
ExploitDB
3 CVEs
2.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (108 CVEs).

Media Mentions

Signals from CVEs in this product scope (108 CVEs).

Top CNAs Publishing CVEs For Owncloud Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.1.435.91.8%00
8.1.345.51.8%00
8.1.145.51.8%00
8.1.076.12.2%00
8.0.924.61.0%00
8.0.824.61.0%00
8.0.624.61.0%00
8.0.555.92.0%00
8.0.465.61.9%00
8.0.3106.44.3%00
8.0.2106.44.3%00
8.0.0106.44.3%00
7.0.736.82.7%00
7.0.646.12.3%00
7.0.566.92.5%00
7.0.466.92.5%00
7.0.366.92.5%00
7.0.2145.71.8%00
7.0.1145.71.8%00
7.0.0145.71.8%00