CVE-2017-0888: Nextcloud

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.

Affected products

  • Nextcloud Nextcloud: up to and including 9.0.54
  • Nextcloud Nextcloud Server: version 10.0.2 only

Published 2017-04-05. Last modified 2026-06-17.