Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:* |
Mon, 01 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud tables |
|
| Vendors & Products |
Nextcloud
Nextcloud tables |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections, the ORDER BY is limited to extracting a single bit of information per request or to make the database wait for a given time. This issue has been patched in versions 0.9.7 and 1.0.2. | |
| Title | Nextcloud: Tables app allows limited SQLi in ORDER BY with malicious sort order argument for Table Views | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T19:33:47.068Z
Reserved: 2026-05-13T05:51:48.666Z
Link: CVE-2026-45722
Updated: 2026-06-01T19:33:40.946Z
Status : Analyzed
Published: 2026-06-01T19:16:52.840
Modified: 2026-06-04T16:50:59.530
Link: CVE-2026-45722
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:45:22Z