CVE-2019-15619: Nextcloud Deck

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

Affected products

  • Nextcloud Deck: before 0.6.6 (fixed in 0.6.6)
  • Nextcloud Nextcloud Server: before 16.0.4 (fixed in 16.0.4)
  • Nextcloud Talk: before 6.0.4 (fixed in 6.0.4)

Published 2020-02-04. Last modified 2026-06-17.