← Vulnerability feed

Vulnerability record · CVE-2026-45722 · published 1 June 2026

CVE-2026-45722: Nextcloud tables sql injection vulnerability

Nextcloud · Tables

Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or to make the database wait for a given time. This issue has been patched in versions 0.9.7 and 1.0.2.

7.1 CVSS 3.1 High EPSS 0.49% · top 60.4% CWE-89 · SQL injection
7.1CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
22 Jul 2026Last modified by NVD

Description

Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or to make the database wait for a given time. This issue has been patched in versions 0.9.7 and 1.0.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45722 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-45545Nextcloud tables sql injection vulnerabilityNextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1…EPSS 0.52%6.5CVE-2024-52511Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b…EPSS 0.46%5.3CVE-2025-66513Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric…EPSS 0.30%4.3CVE-2026-45544Nextcloud tables vulnerabilityNextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users …EPSS 0.37%4.3CVE-2025-66551Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their ow…EPSS 0.25%4.3CVE-2025-66553Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta d…EPSS 0.28%4.3CVE-2024-52507Nextcloud tables insecure direct object reference vulnerabilityNextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and u…EPSS 0.42%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2026-45722), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.