CVE-2020-8235: Nextcloud Deck
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
Affected products
- Nextcloud Deck: version 1.0.4 only
Published 2020-10-05. Last modified 2026-06-17.