CVE-2016-1498: ownCloud
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
Affected products
- ownCloud ownCloud: up to and including 7.0.11; version 8.2.0 only; version 8.2.1 only
- ownCloud ownCloud Server: version 8.0.0 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; version 8.0.6 only; …
Published 2016-01-08. Last modified 2026-06-17.