CVE-2020-8181: Nextcloud Contacts

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.

Affected products

  • Nextcloud Contacts: before 3.3.0 (fixed in 3.3.0)

Published 2020-07-10. Last modified 2026-06-17.