📦

owncloud

Vendor: owncloud

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 5 Remote Access
Total CVEs 522 Total Indexed
Avg. EPSS 1.02% Exploit Prob.
Latest CVE CVE-2022-43679 Nov 10

Security Vulnerability Index

Page 2 / 53
4.3 CVSS

The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.

EPSS: 0.15%
6.1 CVSS

ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.'

EPSS: 0.32%
4.9 CVSS

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

EPSS: 1.29%
9.8 CVSS

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

EPSS: 0.99%
6.5 CVSS

Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

EPSS: 0.25%
5.4 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php.

EPSS: 0.24%
9.8 CVSS

The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

EPSS: 0.82%
5.4 CVSS
CVE-2014-1665
Exploit Found

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

EPSS: 0.34%
6.5 CVSS

An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.

EPSS: 0.21%
5.3 CVSS

A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

EPSS: 0.24%