Description
DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.
Published: 2026-07-06
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weakness, identified as CWE‑79, arises from improper neutralization of user input when pages. embed malicious JavaScript that is stored and later executed in the browsers of any user who views the compromised content.

Affected Systems

Vulnerable versions are ownCloud 10 before 10.15.3 and the embedded DrawIO for ownCloud application before 1.0.2. Organizations running these releases are at risk until the software is updated to the patched versions.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector involves a diagram in the DrawIO app, which stores maliciously crafted input that of any user who views that diagram. With a CVSS score of 8.2 the vulnerability is high severity. The EPSS score is <1%, indicating exploitation likelihood is very low but nonzero. The vulnerability is not listed in the CISA KEV catalog. Furthermore, the description infers that attackers must have access to the DrawIO app, which typically requires authenticated or privileged access within ownCloud.

Generated by OpenCVE AI on July 26, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ownCloud 10 to version 10.15.3 or later.
  • Upgrade DrawIO for ownCloud to version 1.0.2 or later.
  • If patching is delayed, restrict user permissions to the DrawIO app so that only trusted users can add or edit content.

Generated by OpenCVE AI on July 26, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Owncloud
Owncloud drawio For Owncloud
Owncloud owncloud
Vendors & Products Owncloud
Owncloud drawio For Owncloud
Owncloud owncloud

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.
Title DrawIO for ownCloud 10 is vulnerable to Stored XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L'}


Subscriptions

Owncloud Drawio For Owncloud Owncloud
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-06T18:49:06.961Z

Reserved: 2025-07-09T14:14:52.531Z

Link: CVE-2025-53831

cve-icon Vulnrichment

Updated: 2026-07-06T18:49:03.232Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')