CVE-2019-15622: Nextcloud

Low severity, CVSS 2.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

Affected products

  • Nextcloud Nextcloud: before 3.6.1 (fixed in 3.6.1)

Published 2020-02-04. Last modified 2026-06-17.