CVE-2025-66551: Nextcloud Tables

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

Affected products

  • Nextcloud Tables: from 0.4.0, before 0.8.6 (fixed in 0.8.6); from 0.9.0, before 0.9.3 (fixed in 0.9.3)

Published 2025-12-05. Last modified 2026-09-25.