Known vulnerabilities in Talk

Vendor: Nextcloud
Software: Talk
Software CPE: cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 6.9

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Talk Talk is affected by 12 known vulnerabilities: 3 medium, 9 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119223 - Authorization Bypass Through User-Controlled Key
CVE-2025-66556
CWE-639 Medium
No
No
20.1.8, 21.1.2 05.12.2025 SB2025120536
#VU82076 - Improper Restriction of Excessive Authentication Attempts
CVE-2023-45149
CWE-307 Low
No
No
15.0.8, 16.0.6, 17.1.1 17.10.2023 SB2023101717
#VU75180 - Violation of Secure Design Principles
CVE-2023-30540
CWE-657 Low
No
No
15.0.5 18.04.2023 SB2023041805
#VU74601 - Exposure of sensitive information to an unauthorized actor
CVE-2023-28845
CWE-200 Low
No
No
14.0.9, 15.0.4 07.04.2023 SB2023040727
#VU72608 - Exposure of sensitive information to an unauthorized actor
CVE-2023-26041
CWE-200 Low
No
No
15.0.3 28.02.2023 SB2023022803
#VU69801 - Exposure of sensitive information to an unauthorized actor
CVE-2022-41971
CWE-200 Medium
No
No
12.2.8, 13.0.10, 14.0.6, 15.0.0 01.12.2022 SB2022120135
#VU67418 - Exposure of sensitive information to an unauthorized actor
CVE-2022-39212
CWE-200 Low
No
No
13.0.8, 14.0.4 16.09.2022 SB2022091602
#VU66598 - Exposure of sensitive information to an unauthorized actor
CVE-2022-35932
CWE-200 Low
No
No
12.2.7, 13.0.7, 14.0.3 18.08.2022 SB2022081803
#VU63086 - Exposure of sensitive information to an unauthorized actor
CVE-2022-24890
CWE-200 Low
No
No
13.0.5, 14.0.0 12.05.2022 SB2022051203
#VU62647 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-24887
CWE-601 Low
No
No
11.3.4, 12.2.2, 13.0.0 27.04.2022 SB2022042710
#VU61278 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-41180
CWE-601 Medium
No
No
12.1.2 14.03.2022 SB2022031410
#VU57646 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-39222
CWE-79 Low
No
No
10.0.7, 10.1.4, 11.1.2, 11.2.0, 12.0.0 26.10.2021 SB2021102611