Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.
Title Nextcloud Mail stored HTML injection in subject text
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-05T17:32:25.767Z

Reserved: 2025-12-03T15:28:02.992Z

Link: CVE-2025-66514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:57.457

Modified: 2025-12-05T18:15:57.457

Link: CVE-2025-66514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses