CVE-2025-66514

Published
View on NVD ↗
CVSS v3
3.5
LOW
CVSS v2
N/A
Affected
2
PROJECTS

Description

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.

👮 Security advisories of Nextcloud
GitHubGitHub
75
💌 Mail app for Nextcloud
GitHubGitHub
992