Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
History

Tue, 09 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nextcloud:mail:*:*:*:*:*:nextcloud:*:*

Mon, 08 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud mail
Vendors & Products Nextcloud
Nextcloud mail

Fri, 05 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Title Nextcloud Mail stored HTML injection in subject text
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T17:32:25.767Z

Updated: 2025-12-08T20:10:21.710Z

Reserved: 2025-12-03T15:28:02.992Z

Link: CVE-2025-66514

cve-icon Vulnrichment

Updated: 2025-12-08T20:10:15.202Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T18:15:57.457

Modified: 2025-12-09T19:23:19.687

Link: CVE-2025-66514

cve-icon Redhat

No data.