CVE-2014-2052: ownCloud

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Affected products

  • ownCloud ownCloud: before 5.0.15 (fixed in 5.0.15)
  • ownCloud ownCloud Server: from 6.0.0, before 6.0.2 (fixed in 6.0.2)

Published 2020-02-11. Last modified 2026-06-17.