Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-66554


Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.


Published

2025-12-05T18:15:58.630

Last Modified

2025-12-09T17:01:51.250

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud contacts < 5.5.4 Yes
Application nextcloud contacts < 6.0.6 Yes
Application nextcloud contacts < 7.2.5 Yes

References