Known vulnerabilities in Nextcloud Enterprise Server

Vendor: Nextcloud
Software CPE: cpe:2.3:a:nextcloud:nextcloud_enterprise_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 55
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Nextcloud Enterprise Server Nextcloud Enterprise Server is affected by 55 known vulnerabilities: 2 high, 18 medium, 35 low Critical High Medium Low

Vulnerabilities (55)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141394 - Improper Access Control
CVE-2026-61527
CWE-284 Medium
No
No
32.0.12, 33.0.6 10.08.2026 SB2026081040
#VU119229 - Insufficient Logging
CVE-2025-66552
CWE-778 Medium
No
No
30.0.9, 31.0.1 05.12.2025 SB2025120555
#VU119228 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-66512
CWE-79 Low
No
No
31.0.12, 32.0.3 05.12.2025 SB2025120554
#VU119219 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-59788
CWE-79 Low
No
No
22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 05.12.2025 SB2025120550
#VU103063 - Exposure of sensitive information to an unauthorized actor
CVE-2024-52517
CWE-200 Low
No
No
25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8, 30.0.1 20.01.2025 SB2025012097
#VU103062 - Cleartext Storage of Sensitive Information
CVE-2024-52525
CWE-312 Low
No
No
28.0.12, 29.0.9, 30.0.2 20.01.2025 SB2025012096
#VU103061 - Improper Authentication
CVE-2024-52518
CWE-287 Low
No
No
28.0.12, 29.0.9, 30.0.2 20.01.2025 SB2025012096
#VU103060 - Resource exhaustion
CVE-2024-52520
CWE-400 Medium
No
No
27.1.11.8, 28.0.10, 29.0.7 20.01.2025 SB2025012094
#VU103059 - Improper Access Control
CVE-2024-52514
CWE-284 Low
No
No
21.0.9.18, 22.2.10.23, 23.0.12.18, 24.0.12.14, 25.0.13.9, 26.0.13.3, 27.1.9, 28.0.5, 29.0.0 20.01.2025 SB2025012095
#VU103058 - Insecure Storage of Sensitive Information
CVE-2024-52519
CWE-922 Low
No
No
27.1.11.8, 28.0.10, 29.0.7 20.01.2025 SB2025012094
#VU103057 - Use of Incorrectly-Resolved Name or Reference
CVE-2024-52515
CWE-706 Medium
No
No
24.0.12.15, 25.0.13.10, 26.0.13.4, 27.1.10, 28.0.6, 29.0.1 20.01.2025 SB2025012093
#VU103056 - Exposure of sensitive information to an unauthorized actor
CVE-2024-52523
CWE-200 Low
No
No
25.0.13.14, 26.0.13.10, 27.1.11.10, 28.0.12, 29.0.9, 30.0.2 20.01.2025 SB2025012092
#VU103055 - Improper Privilege Management
CVE-2024-52516
CWE-269 Low
No
No
26.0.13.9, 27.1.11.9, 28.0.9, 29.0.5 20.01.2025 SB2025012091
#VU103052 - Use of Weak Hash
CVE-2024-52521
CWE-328 Low
No
No
28.0.10, 29.0.7, 30.0.0 20.01.2025 SB2025012090
#VU84547 - Improper Access Control
CVE-2023-49791
CWE-284 Medium
No
No
23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, 27.1.4 19.12.2023 SB2023121925
#VU84543 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-49792
CWE-307 Medium
No
No
23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, 27.1.4 19.12.2023 SB2023121925
#VU83361 - Authorization Bypass Through User-Controlled Key
CVE-2023-48304
CWE-639 Low
No
No
22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112137
#VU83360 - Improper Access Control
CVE-2023-48239
CWE-284 Medium
No
No
20.0.14.16, 21.0.9.13, 22.2.10.15, 23.0.12.12, 24.0.12.8, 25.0.13, 26.0.8, 27.1.3 21.11.2023 SB2023112136
#VU83359 - Server-Side Request Forgery (SSRF)
CVE-2023-48306
CWE-918 Medium
No
No
22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112137
#VU83358 - Cleartext Storage of Sensitive Information
CVE-2023-48305
CWE-312 Low
No
No
25.0.11, 26.0.6, 27.1.0 21.11.2023 SB2023112135


Showing elements 1 - 20 out of 55