Nextcloud

Deck

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 18.09.2026 01:26:04
  • Zuletzt bearbeitet 18.09.2026 20:17:22

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

  • EPSS 0.27%
  • Veröffentlicht 05.12.2025 17:28:48
  • Zuletzt bearbeitet 25.09.2026 23:10:00

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permission to modify ...

  • EPSS 0.15%
  • Veröffentlicht 05.12.2025 17:26:11
  • Zuletzt bearbeitet 09.12.2025 19:01:55

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users in...

  • EPSS 0.38%
  • Veröffentlicht 14.06.2024 16:15:13
  • Zuletzt bearbeitet 21.11.2024 09:24:27

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 18.01.2024 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:55:48

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML s...

  • EPSS 0.52%
  • Veröffentlicht 14.01.2023 01:15:14
  • Zuletzt bearbeitet 21.11.2024 07:44:52

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It i...

  • EPSS 0.66%
  • Veröffentlicht 14.01.2023 01:15:13
  • Zuletzt bearbeitet 21.11.2024 07:44:52

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 10.01.2023 21:15:12
  • Zuletzt bearbeitet 21.11.2024 07:44:52

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards the user has no access to, unauthorized user could eventually get the ...

Exploit
  • EPSS 0.97%
  • Veröffentlicht 20.05.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:36

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app ...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 20.05.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:22

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1....