Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/mail/commit/c64fcc3b79e0c089b5e1d2e04a07bfa740b2ac09 | Patch |
| https://github.com/nextcloud/mail/pull/11740 | Issue Tracking Patch |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-v394-8gpc-6fv5 | Patch Vendor Advisory |
| https://hackerone.com/reports/3357036 | Permissions Required Vendor Advisory |
Configurations
History
09 Dec 2025, 19:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/mail/commit/c64fcc3b79e0c089b5e1d2e04a07bfa740b2ac09 - Patch | |
| References | () https://github.com/nextcloud/mail/pull/11740 - Issue Tracking, Patch | |
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-v394-8gpc-6fv5 - Patch, Vendor Advisory | |
| References | () https://hackerone.com/reports/3357036 - Permissions Required, Vendor Advisory | |
| CPE | cpe:2.3:a:nextcloud:mail:*:*:*:*:*:nextcloud:*:* | |
| First Time |
Nextcloud
Nextcloud mail |
05 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 18:15
Updated : 2025-12-09 19:23
NVD link : CVE-2025-66514
Mitre link : CVE-2025-66514
CVE.ORG link : CVE-2025-66514
JSON object : View
Products Affected
nextcloud
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
