← Vulnerability feed

Vulnerability record · CVE-2025-47793 · published 16 May 2025

CVE-2025-47793: Nextcloud group folders allocation without limits vulnerability

Nextcloud · Group Folders

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.

6.5 CVSS 3.1 Medium EPSS 0.79% · top 45.6% CWE-770 · Allocation without limits
6.5CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49792Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…EPSS 1.0%9.8CVE-2023-48306Nextcloud server server-side request forgery (ssrf) vulnerabilityNextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6…EPSS 0.80%9.8CVE-2021-32802Nextcloud server inclusion from untrusted sphere vulnerabilityNextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some …EPSS 2.6%9.8CVE-2021-32726Nextcloud server improper authentication vulnerabilityNextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted…EPSS 1.8%9.8CVE-2021-22915Nextcloud server improper restriction of authentication attempts vulnerabilityNextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting consi…EPSS 1.7%9.1CVE-2023-35172Nextcloud server improper restriction of authentication attempts vulnerabilityNextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server version…EPSS 0.92%9.1CVE-2021-32654Nextcloud server insecure direct object reference vulnerabilityNextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …EPSS 1.8%8.8CVE-2023-45151Nextcloud server cleartext storage of sensitive data vulnerabilityNextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2025-47793), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.