These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-53830 is a Server-Side Request Forgery (SSRF) vulnerability affecting Anti-Virus for ownCloud versions before 1.2.3, corresponding to ownCloud 10 prior to 10.15.3. The vulnerability allows attackers to manipulate server-side requests, potentially leading to unauthorized access and data breaches. Users should prioritize upgrading to the fixed versions to prevent potential SSRF attacks. The vulnera [truncated]
A path traversal vulnerability exists in ownCloud 10 prior to version 10.15.3, allowing an attacker with administrative privileges to execute arbitrary code. This vulnerability is addressed in ownCloud 10 version 10.15.3 or later. The vulnerability is due to insufficient validation of user input, enabling an attacker to traverse the file system and execute code. ownCloud 10 users should upgrade to the pat [truncated]
CVE-2025-53828 is a high-severity SSRF vulnerability in SharePoint for ownCloud. An attacker with administrative privileges can exploit this vulnerability to execute arbitrary code on the system. The vulnerability affects SharePoint for ownCloud prior to version 0.4.1, corresponding to ownCloud 10 prior to 10.15.3. To mitigate this vulnerability, users should upgrade ownCloud 10 to version 10.15.3 or late [truncated]
The CVE record for CVE-2025-53827 was published on 2026-07-06T16:16:26.740Z and has not been modified since then. The NVD entry is currently Deferred. ownCloud Core, the server-side component of the file storage, synchronization, and sharing application ownCloud Classic, has a vulnerability in the Updater component. In versions prior to 10.15.3, the Updater has an exposed dangerous method or function that [truncated]
CVE-2023-49103 is a CISA Known Exploited Vulnerabilities entry affecting ownCloud graphapi. The public records provided here describe it as an information disclosure vulnerability, and CISA’s note points to vendor guidance about disclosure of sensitive credentials and configuration in containerized deployments. Because CISA added it to KEV on 2023-11-30 with a remediation due date of 2023-12-21, defenders [truncated]
CVE-2017-5867 describes a denial-of-service issue in ownCloud Server where a remote authenticated user can trigger a server hang and logfile flooding by uploading or processing a one-bit BMP file. The issue affects multiple ownCloud release lines and is addressed by vendor-fixed versions.
CVE-2017-5866 is a low-severity information disclosure issue in ownCloud Server’s E-Mail share dialog autocomplete feature. The flaw affects specific ownCloud releases before the vendor’s fixed versions and allows a remote authenticated user to obtain sensitive information. The NVD assigns CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, reflecting limited confidentiality impact with no integrity or a [truncated]
CVE-2017-5865 is an information-disclosure issue in ownCloud Server's password-reset flow. In affected versions, the application returned different error messages depending on whether a username was valid, which let remote attackers enumerate user names by repeatedly attempting password resets. The fix is to move to a patched release and ensure the reset flow does not reveal account existence through its responses.
CVE-2016-7102 describes a local code execution issue in ownCloud Desktop before version 2.2.3. According to the CVE/NVD record, a malicious library placed in a special path on the C: drive could be loaded, allowing arbitrary code execution by a local user and possibly privilege gain.
CVE-2016-5876 affects ownCloud server installations when the gallery app is enabled. The issue allows a remote attacker to download arbitrary images through a direct request. NVD rates the weakness as Medium severity (CVSS 5.9) with network attack vector, no privileges required, and no user interaction.