CVE-2017-8896: ownCloud

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.

Affected products

  • ownCloud ownCloud: up to and including 8.2.11; from 9.0.0, up to and including 9.0.9; after 9.1.0, up to and including 9.1.5; from 10.0.0, before 10.0.2 (fixed in 10.0.2)

Published 2017-07-17. Last modified 2026-06-17.