CVE-2019-15618: Nextcloud Server

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

Affected products

  • Nextcloud Nextcloud Server: before 14.0.9 (fixed in 14.0.9); from 15.0.0, before 15.0.6 (fixed in 15.0.6)

Published 2020-02-04. Last modified 2026-06-17.