CVE-2023-39955: Nextcloud Notes
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
Affected products
- Nextcloud Notes: from 4.4.0, before 4.8.0 (fixed in 4.8.0)
Published 2023-08-10. Last modified 2026-06-17.