CVE-2025-66513: Nextcloud Tables

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.

Affected products

  • Nextcloud Tables: from 0.6.0, before 0.8.9 (fixed in 0.8.9); from 0.9.0, before 0.9.6 (fixed in 0.9.6); from 1.0.0, before 1.0.1 (fixed in 1.0.1)

Published 2025-12-05. Last modified 2026-06-17.