We found results for “”
CVE-2025-66545
Good to know:
Date: December 5, 2025
Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization
CWE-707Top Fix
Upgrade Version
Upgrade to version https://github.com/nextcloud/groupfolders.git - v14.0.11;https://github.com/nextcloud/groupfolders.git - v15.3.12;https://github.com/nextcloud/groupfolders.git - v16.0.15;https://github.com/nextcloud/groupfolders.git - v17.0.14;https://github.com/nextcloud/groupfolders.git - v18.1.8;https://github.com/nextcloud/groupfolders.git - v19.1.8;https://github.com/nextcloud/groupfolders.git - v20.1.2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


