Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/nextcloud/tables

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Nextcloud versions 0.9.0 to before 0.9.7 and 1.0.0 to before 1.0.2 contain a SQL injection vulnerability in the Tables app due to missing sanitization in the ORDER BY clause of a query. This flaw allows a user with access to the Tables app to perform limited SQL injection attacks that can extract a single bit of information per request or cause the database to delay responses.

Join the discussion

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue has been patched in versions 0.7.7, 0.8.10, 0.9.8, 1.0.4, and 2.0.0.

Join the discussion

Nextcloud versions from 0.8.0 up to but not including 1.0.4 have a vulnerability where view filter criteria in Nextcloud Tables are exposed to users with read-only permissions. This exposure of metadata could reveal sensitive information unintentionally. The issue has been addressed and patched in versions 1.0.4 and later.

Join the discussion

CVE-2025-66553 is a medium-severity authorization bypass vulnerability in Nextcloud Tables versions prior to 0.8.7 and between 0.9.0-beta.1 and 0.9.4. Authenticated users could manipulate numeric IDs in requests to view metadata of columns in other users' tables, exposing potentially sensitive schema information. This vulnerability does not allow modification or deletion of data, nor does it require user interaction beyond authentication.

Join the discussion

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

Join the discussion

CVE-2025-66513 is a medium severity authorization bypass vulnerability in Nextcloud Tables versions prior to 0.8.9, 0.9.6, and 1.0.1. It allows unauthorized users to access information about which tables are shared with which groups or users and their permissions, due to insufficient access control on user-controlled keys. Exploitation requires network access and some user interaction but no privileges. The vulnerability impacts confidentiality but not integrity or availability.

Join the discussion

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/nextcloud/tables
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses