Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.
2025-12-05T17:16:04.980
2025-12-09T16:38:19.160
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nextcloud | nextcloud_server | < 31.0.12 | Yes |
| Application | nextcloud | nextcloud_server | < 31.0.12 | Yes |
| Application | nextcloud | nextcloud_server | < 32.0.3 | Yes |
| Application | nextcloud | nextcloud_server | < 32.0.3 | Yes |