QSearchQSearch

CVE-2026-45545

8.2 HIGH

Nextcloud is an open source content collaboration platform

Published: 2026-06-01 · Last updated: 2026-06-04

Severity and scoring

CVSS
8.2 HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE
CWE-89

Affected products

VendorProduct
nextcloudtables

Description

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-45810 Nextcloud is an open source content collaboration platform (6.8 MEDIUM)
  • CVE-2026-45722 Nextcloud is an open source content collaboration platform (7.1 HIGH)
  • CVE-2026-45691 Nextcloud is an open source content collaboration platform (5.9 MEDIUM)
  • CVE-2026-45690 Nextcloud is an open source content collaboration platform (5.9 MEDIUM)
  • CVE-2026-45544 Nextcloud is an open source content collaboration platform (4.3 MEDIUM)

Same CWE

  • CVE-2026-53474 A flaw was found in migration-planner (9.6 CRITICAL)
  • CVE-2026-52758 Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL qu... (8.8 HIGH)
  • CVE-2026-49498 Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to e... (8.8 HIGH)
  • CVE-2026-3018 The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up t... (7.5 HIGH)
  • CVE-2026-3326 The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX ... (8.6 HIGH)