CVE-2019-5449: Nextcloud Server

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

Affected products

  • Nextcloud Nextcloud Server: before 15.0.1 (fixed in 15.0.1)

Published 2019-07-30. Last modified 2026-06-17.