CVE-2014-9042: ownCloud

Low severity, CVSS 3.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote authenticated users to inject arbitrary web script or HTML by importing a link with an unspecified protocol. NOTE: this can be leveraged by remote attackers using CVE-2014-9041.

Affected products

  • ownCloud ownCloud: up to and including 5.0.17
  • ownCloud ownCloud Server: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only; version 5.0.5 only; …

Published 2015-02-04. Last modified 2026-06-17.