← Vulnerability feed

Vulnerability record · CVE-2019-15624 · published 4 February 2020

CVE-2019-15624: Nextcloud server improper input validation vulnerability

Nextcloud · Nextcloud Server

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

4.9 CVSS 3.1 Medium EPSS 1.5% · top 27.1% CWE-20 · Improper input validation
4.9CVSS 3.1 base score, v2 4.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2016-3714ImageMagick coders allow command execution via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 fail to validate input in multiple coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT), allo…KEVEPSS 97%analysed5.5CVE-2014-0196Linux kernel n_tty_write race condition allows local privilege escalationThe n_tty_write function in the Linux kernel through 3.14.3 mishandles tty driver access in the LECHO & !OPOST case, creating a race condition betwee…KEVEPSS 22%analysed10.0CVE-2015-2738Canonical ubuntu linux vulnerabilityThe YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8…EPSS 2.7%10.0CVE-2015-2737Mozilla firefox vulnerabilityThe rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before …EPSS 2.7%10.0CVE-2015-2734Suse linux enterprise desktop vulnerabilityThe CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 a…EPSS 2.7%10.0CVE-2014-2978Directfb memory buffer overflow vulnerabilityThe Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service …EPSS 6.1%10.0CVE-2014-2977Opensuse vulnerabilityMultiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote a…EPSS 6.8%10.0CVE-2014-1512Mozilla firefox use after free vulnerabilityUse-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbi…EPSS 29%

Source: NIST National Vulnerability Database (record CVE-2019-15624), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.