CVE-2025-66545
05.12.2025, 18:15
Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | group_folders | 𝑥 < 14.0.11 |
| nextcloud | group_folders | 15.0.0 ≤ 𝑥 < 15.3.12 |
| nextcloud | group_folders | 16.0.0 ≤ 𝑥 < 16.0.15 |
| nextcloud | group_folders | 17.0.0 ≤ 𝑥 < 17.0.14 |
| nextcloud | group_folders | 18.0.0 ≤ 𝑥 < 18.1.8 |
| nextcloud | group_folders | 19.0.0 ≤ 𝑥 < 20.1.2 |
𝑥
= Vulnerable software versions