CVE-2020-8181: Nextcloud Contacts
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
Affected products
- Nextcloud Contacts: before 3.3.0 (fixed in 3.3.0)
Published 2020-07-10. Last modified 2026-06-17.