PatchSiren

owncloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL owncloud CVE published 2026-07-06

CVE-2025-53830

CVE-2025-53830 is a Server-Side Request Forgery (SSRF) vulnerability affecting Anti-Virus for ownCloud versions before 1.2.3, corresponding to ownCloud 10 prior to 10.15.3. The vulnerability allows attackers to manipulate server-side requests, potentially leading to unauthorized access and data breaches. Users should prioritize upgrading to the fixed versions to prevent potential SSRF attacks. The vulnera [truncated]

HIGH owncloud CVE published 2026-07-06

CVE-2025-53829

A path traversal vulnerability exists in ownCloud 10 prior to version 10.15.3, allowing an attacker with administrative privileges to execute arbitrary code. This vulnerability is addressed in ownCloud 10 version 10.15.3 or later. The vulnerability is due to insufficient validation of user input, enabling an attacker to traverse the file system and execute code. ownCloud 10 users should upgrade to the pat [truncated]

HIGH owncloud CVE published 2026-07-06

CVE-2025-53828

CVE-2025-53828 is a high-severity SSRF vulnerability in SharePoint for ownCloud. An attacker with administrative privileges can exploit this vulnerability to execute arbitrary code on the system. The vulnerability affects SharePoint for ownCloud prior to version 0.4.1, corresponding to ownCloud 10 prior to 10.15.3. To mitigate this vulnerability, users should upgrade ownCloud 10 to version 10.15.3 or late [truncated]

CRITICAL ownCloud CVE published 2026-07-06

CVE-2025-53827

The CVE record for CVE-2025-53827 was published on 2026-07-06T16:16:26.740Z and has not been modified since then. The NVD entry is currently Deferred. ownCloud Core, the server-side component of the file storage, synchronization, and sharing application ownCloud Classic, has a vulnerability in the Updater component. In versions prior to 10.15.3, the Updater has an exposed dangerous method or function that [truncated]

Known exploited ownCloud CVE published 2023-11-30

CVE-2023-49103

CVE-2023-49103 is a CISA Known Exploited Vulnerabilities entry affecting ownCloud graphapi. The public records provided here describe it as an information disclosure vulnerability, and CISA’s note points to vendor guidance about disclosure of sensitive credentials and configuration in containerized deployments. Because CISA added it to KEV on 2023-11-30 with a remediation due date of 2023-12-21, defenders [truncated]

MEDIUM Owncloud CVE published 2017-03-03

CVE-2017-5867

CVE-2017-5867 describes a denial-of-service issue in ownCloud Server where a remote authenticated user can trigger a server hang and logfile flooding by uploading or processing a one-bit BMP file. The issue affects multiple ownCloud release lines and is addressed by vendor-fixed versions.

MEDIUM Owncloud CVE published 2017-03-03

CVE-2017-5866

CVE-2017-5866 is a low-severity information disclosure issue in ownCloud Server’s E-Mail share dialog autocomplete feature. The flaw affects specific ownCloud releases before the vendor’s fixed versions and allows a remote authenticated user to obtain sensitive information. The NVD assigns CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, reflecting limited confidentiality impact with no integrity or a [truncated]

LOW Owncloud CVE published 2017-03-03

CVE-2017-5865

CVE-2017-5865 is an information-disclosure issue in ownCloud Server's password-reset flow. In affected versions, the application returned different error messages depending on whether a username was valid, which let remote attackers enumerate user names by repeatedly attempting password resets. The fix is to move to a patched release and ensure the reset flow does not reveal account existence through its responses.

HIGH Owncloud CVE published 2017-01-23

CVE-2016-7102

CVE-2016-7102 describes a local code execution issue in ownCloud Desktop before version 2.2.3. According to the CVE/NVD record, a malicious library placed in a special path on the C: drive could be loaded, allowing arbitrary code execution by a local user and possibly privilege gain.

MEDIUM Owncloud CVE published 2017-01-23

CVE-2016-5876

CVE-2016-5876 affects ownCloud server installations when the gallery app is enabled. The issue allows a remote attacker to download arbitrary images through a direct request. NVD rates the weakness as Medium severity (CVSS 5.9) with network attack vector, no privileges required, and no user interaction.