CVE-2019-5454: Nextcloud

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

Affected products

  • Nextcloud Nextcloud: version 1.0.0 only; version 1.0.1 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.3.1 only; …

Published 2019-07-30. Last modified 2026-06-17.