Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
History

Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nextcloud:contacts:*:*:*:*:*:*:*:*

Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud contacts
Vendors & Products Nextcloud
Nextcloud contacts

Mon, 08 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
Description Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.
Title Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T17:50:59.860Z

Updated: 2025-12-08T19:51:03.328Z

Reserved: 2025-12-04T15:57:22.035Z

Link: CVE-2025-66554

cve-icon Vulnrichment

Updated: 2025-12-08T19:50:57.903Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T18:15:58.630

Modified: 2025-12-09T17:01:51.250

Link: CVE-2025-66554

cve-icon Redhat

No data.