Brand
ownCloud: actively exploited vulnerabilities
2 vulnerabilities in ownCloud products (ownCloud Server) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 27, 2026.
-
1 vulnerability added in the last 12 months
-
2 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one ownCloud category to your radar, or open its page.
- Managed file transfer (MFT) 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- ownCloud Server2 vulnerabilities, File transfer (MFT)
Name used by CISA: ownCloud. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this ownCloud list.
- Rank 1
ownCloud ServerCVE-2023-49105
ownCloud Improper Authentication Vulnerability
Hunt for compromise (CISA)CVE from 2023, added in 2026
CVSS severity 9.8critical
Added Aug 27, 2026
- Rank 2
ownCloud ServerCVE-2023-49103
ownCloud graphapi Information Disclosure Vulnerability
CVSS severity 7.5high
Added Nov 30, 2023
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.