Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Owncloud

246 known vulnerabilities

6
CRITICAL
11
HIGH
39
MEDIUM
5
LOW

Top Products

owncloud 40 owncloud server 12 owncloud client 6 owncloud desktop client 3 files antivirus 3 guests 1 oauth2 1 graph api 1 user ldap 1 file firewall 1
61 CVEs · Page 1/2
5.3
CVE-2025-59716

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp

9.8
CVE-2023-49105 KEV

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit

8.7
CVE-2023-49104

An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able

10.0
CVE-2023-49103 KEV

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies

5.0
CVE-2023-24804

The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the a

6.2
CVE-2023-23948

The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCl

4.2
CVE-2022-43679

The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config us

7.5
CVE-2022-31649

ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

5.5
CVE-2022-25339

ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.

6.8
CVE-2022-25338

ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.

7.8
CVE-2021-44537

ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t

8.8
CVE-2021-33828

The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th

7.2
CVE-2021-33827

The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

2.7
CVE-2021-40537

Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap

5.4
CVE-2021-35948

Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass th

9.8
CVE-2021-35946

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio

5.3
CVE-2021-35949

The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upl

5.3
CVE-2021-35947

The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal pa

6.5
CVE-2021-29659

ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in t

7.8
CVE-2020-28646

ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir

3.9
CVE-2020-36248

The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac

6.8
CVE-2020-36252

ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version o

3.5
CVE-2020-36251

ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove

6.1
CVE-2020-36250

In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system

7.5
CVE-2020-36249

The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.

5.9
CVE-2020-10254

An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by

8.3
CVE-2020-10252

An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa

9.1
CVE-2020-28645

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to reg

4.3
CVE-2020-28644

The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against so

5.7
CVE-2020-16144

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous us

6.1
CVE-2020-16255

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

4.9
CVE-2015-4715

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x

9.8
CVE-2014-2052

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitra

6.5
CVE-2014-2050

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at

6.1
CVE-2013-0202

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr

5.4
CVE-2013-0203

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inj

9.8
CVE-2014-2048

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure

5.4
CVE-2014-1665

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary

6.5
CVE-2017-9340

An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before

5.3
CVE-2017-9339

A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus gran

5.4
CVE-2017-9338

Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10

6.1
CVE-2017-8896

ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS o

5.3
CVE-2016-9468

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the d

5.3
CVE-2016-9467

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the f

6.1
CVE-2016-9466

Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery applica

5.4
CVE-2016-9465

Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export.

8.1
CVE-2016-9463

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authenti

4.3
CVE-2016-9462

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restori

4.3
CVE-2016-9461

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDA

5.3
CVE-2016-9460

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files a

Frequently Asked Questions

How many CVEs affect Owncloud?

Owncloud has 246 CVE records in our database, including 7 critical and 32 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Owncloud vulnerabilities?

Owncloud has 7 critical severity (CVSS 9.0+) and 32 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Owncloud vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Owncloud products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Owncloud Vulnerabilities

CyberStrike scans your infrastructure for Owncloud vulnerabilities and provides real-time remediation guidance.

Get Started