Total vulnerabilities in the database
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
Software | From | Fixed in |
---|---|---|
nextcloud / nextcloud_server | 15.0.0 | 15.0.6 |
nextcloud / nextcloud_server | - | 14.0.9 |