CVE-2025-47793 Details
Description
Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to 18.0.3, 17.0.5, and 16.0.11, the absence of quota checking on attachments allowed logged-in users to upload files exceeding the group folder quota. Nextcloud Server versions 30.0.2 and 29.0.9, Nextcloud Enterprise Server versions 30.0.2, 29.0.9, or 28.0.12, and Nextcloud Groupfolders app 18.0.3, 17.0.5, and 16.0.11 fix the issue. No known workarounds are available.
A vulnerability in Nextcloud Server, Nextcloud Enterprise Server, and the Nextcloud Groupfolders app allows logged-in users to upload files that exceed the designated group folder quota. This issue arises from a lack of proper quota enforcement on attachments, enabling users to bypass storage limits. The vulnerability is present in Nextcloud Server versions 30.0.0 prior to 30.0.2, 29.0.0 prior to 29.0.9, and 28.0.0 prior to 28.0.1, as well as in Nextcloud Enterprise Server versions 30.0.0 prior to 30.0.2, and 29.0.0 prior to 29.0.9. Additionally, the vulnerability affects Nextcloud Groupfolders app versions 18.0.0 through 18.0.2, 17.0.0 through 17.0.4, and 16.0.0 through 16.0.10.
Users are advised to update Nextcloud Server to version 30.0.2 or 29.0.9, Nextcloud Enterprise Server to version 30.0.2, 29.0.9 or 28.0.12, and the Nextcloud Groupfolders app to version 18.0.3, 17.0.5 or 16.0.11.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud group folders | >= 16.0.0, < 16.0.11 >= 17.0.0, < 17.0.5 >= 18.0.0, < 18.0.3 |
CPE
Remediation
| |
| nextcloud nextcloud server | >= 28.0.0, < 28.0.12 >= 29.0.0, < 29.0.9 >= 30.0.0, < 30.0.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2025 | Initial Analysis | [email protected] |
| May 16, 2025 | New CVE Received | [email protected] |