CVE-2019-5476: Nextcloud Lookup-Server
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
Affected products
- Nextcloud Lookup-Server: before 0.3.0 (fixed in 0.3.0)
Published 2019-08-07. Last modified 2026-06-17.