CVE-2025-66553: Nextcloud Tables

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.

Affected products

  • Nextcloud Tables: from 0.8.0, before 0.8.7 (fixed in 0.8.7); from 0.9.0, before 0.9.4 (fixed in 0.9.4)

Published 2025-12-05. Last modified 2026-06-17.