Vulnerabilities
Vulnerable Software
Nextcloud:  >> Desktop  >> 3.14.4  Security Vulnerabilities
Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This vulnerability is fixed in 3.16.5.
CVSS Score
2.4
EPSS Score
0.0
Published
2025-12-05
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.
CVSS Score
5.0
EPSS Score
0.0
Published
2025-05-16


Contact Us

Shodan ® - All rights reserved