Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-77166 1 Nextcloud 1 Collectives 2026-09-21 N/A
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
CVE-2026-45154 1 Nextcloud 1 Collectives 2026-06-02 2.6 Low
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.