Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-66547


Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.


Published

2025-12-05T17:16:05.330

Last Modified

2025-12-09T16:31:38.237

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_server < 31.0.1 Yes
Application nextcloud nextcloud_server < 31.0.1 Yes

References