Back to Database
Status published
Medium
CVE-2025-66547
Nextcloud Server users can modify tags on files that do not belong to them
Vulnerability Description
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66547
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hq6c-r898-fgf2
- https://github.com/nextcloud/server/issues/51247
- https://github.com/nextcloud/server/pull/51288
- https://github.com/nextcloud/server/commit/b44f1568f2dc97c746281d99e2342ad679e3d8a9
- https://hackerone.com/reports/3040887
More from nextcloud
View All →CVE-2025-66558
Nextcloud Twofactor WebAuthn app was updated based on public key
Low
3.1
CVE-2025-66557
Nextcloud Deck app allowed user with "Can share" permission to modify permissions of other non-owners
Medium
5.4
CVE-2025-66556
Nextcloud talk allows participants to blindly delete poll drafts of other users by ID
Low
3.5
CVE-2025-66554
Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Low
3.5
CVE-2025-66553
Nextcloud Tables app allowed users to view columns metadata information of any table
Medium
4.3
Affected Vendor
nextcloud
View all reports →Affected Software
security-advisories
Vulnerable Versions:
< 31.0.1
Timeline
Official Publish:
December 5th, 2025
Last Modified:
December 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N