Nextcloud Calendar
By the Year
In 2024 there have been 0 vulnerabilities in Nextcloud Calendar . Last year Calendar had 3 security vulnerabilities published. Right now, Calendar is on track to have less security vulnerabilities in 2024 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 3 | 5.03 |
2022 | 1 | 9.80 |
2021 | 0 | 0.00 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 1 | 4.80 |
It may take a day or so for new Calendar vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Nextcloud Calendar Security Vulnerabilities
Nextcloud/Cloud is a calendar app for Nextcloud
CVE-2023-48308
6.5 - Medium
- December 22, 2023
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3
Improper Removal of Sensitive Information Before Storage or Transfer
Nextcloud calendar is a calendar app for the Nextcloud server platform
CVE-2023-45150
4.3 - Medium
- October 16, 2023
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It is recommended that the Nextcloud Calendar app is upgraded to 4.4.4. The only workaround for users unable to upgrade is to disable the calendar app.
Improper Validation of Integrity Check Value
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud
CVE-2023-33183
4.3 - Medium
- May 30, 2023
Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3
Nextcloud Calendar is a calendar application for the nextcloud framework
CVE-2022-24838
9.8 - Critical
- April 11, 2022
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:<BOOKING USER'S EMAIL> ` SMTP command and begin injecting arbitrary SMTP commands. It is recommended that Calendar is upgraded to 3.2.2. There are no workaround available.
Injection
In Nextcloud Calendar before 1.5.8 and 1.6.1
CVE-2018-3763
4.8 - Medium
- July 05, 2018
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Nextcloud Calendar or by Nextcloud? Click the Watch button to subscribe.