Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud nextcloud Server
|
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Nextcloud nextcloud Server
|
Thu, 11 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud in Nextcloud’s PDF viewer with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367. | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, and 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367, but the root cause of this Nextcloud issue is that the product exposes executable example code on a same-origin basis. |
Thu, 04 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud in Nextcloud’s PDF viewer with versions before 22.2.10.33, 23.0.12.29, 24.0.12.28, 25.0.13.23, 26.0.13.20, 27.1.11.20, 28.0.14.11, 29.0.16.8, 30.0.17, 31.0.10, 32.0.1 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted PDF file to viewer.html. This issue is related to CVE-2024-4367. | |
| First Time appeared |
Nextcloud
Nextcloud nextcloud |
|
| Weaknesses | CWE-749 | |
| CPEs | cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextcloud
Nextcloud nextcloud |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-11T15:04:25.726Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59788
Updated: 2025-12-05T17:20:02.577Z
Status : Analyzed
Published: 2025-12-04T19:16:04.380
Modified: 2026-03-25T21:35:25.477
Link: CVE-2025-59788
No data.
OpenCVE Enrichment
No data.