CVE-2016-1499: ownCloud
High severity, CVSS 8.5. EPSS: 3.5% chance of exploitation in the next 30 days.
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.
Affected products
- ownCloud ownCloud: up to and including 8.0.9; version 8.2.0 only; version 8.2.1 only
- ownCloud ownCloud Server: version 8.1.0 only; version 8.1.1 only; version 8.1.3 only; version 8.1.4 only
Published 2016-01-08. Last modified 2026-06-17.