Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-47794

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.

  • Published: May 16, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-47794
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 2.6
  • AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N