CVE-2020-8235: Nextcloud Deck

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

Affected products

Published 2020-10-05. Last modified 2026-06-17.