CVE-2022-24906: Nextcloud Deck

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.

Affected products

  • Nextcloud Deck: before 1.2.11 (fixed in 1.2.11); from 1.4.0, before 1.4.6 (fixed in 1.4.6); from 1.5.0, before 1.5.4 (fixed in 1.5.4)

Published 2022-05-20. Last modified 2026-06-17.