Owncloud
246 known vulnerabilities
Top Products
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit
An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the a
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCl
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config us
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass th
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upl
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal pa
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in t
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain dir
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a bac
ownCloud Server 10.x before 10.3.1 allows an attacker, who has one outgoing share from a victim, to access any version o
ownCloud Server before 10.3.0 allows an attacker, who has received non-administrative access to a group share, to remove
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system
The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to reg
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against so
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous us
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitra
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote at
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitr
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inj
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus gran
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS o
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the d
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the f
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery applica
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export.
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authenti
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restori
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDA
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files a
Frequently Asked Questions
How many CVEs affect Owncloud?
Owncloud has 246 CVE records in our database, including 7 critical and 32 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Owncloud vulnerabilities?
Owncloud has 7 critical severity (CVSS 9.0+) and 32 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Owncloud vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Owncloud products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Owncloud Vulnerabilities
CyberStrike scans your infrastructure for Owncloud vulnerabilities and provides real-time remediation guidance.
Get Started