216.73.216.226

CVE-2025-58051

· Published 16/10/2025 17:15 · Modified 16/10/2025 17:15

Labels: CVE-2025-58051 2025-10-16CVE-2025-58051CWE-841[email protected]

Essential information

Published
16/10/2025 17:15
Modified
16/10/2025 17:15
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is recommended that the Nextcloud Tables app is upgraded to 0.7.6, 0.8.8 or 0.9.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nextcloud / tables cpe:2.3:a:nextcloud:tables:0.7.6:*:*:*:*:*:*:*
nextcloud / tables cpe:2.3:a:nextcloud:tables:0.8.8:*:*:*:*:*:*:*
nextcloud / tables cpe:2.3:a:nextcloud:tables:0.9.5:*:*:*:*:*:*:*

References