Cross-Site Scripting Vulnerability in Nextcloud PDF Viewer
CVE-2025-59788
6.4MEDIUM
What is CVE-2025-59788?
A Cross-site Scripting (XSS) vulnerability exists in the Nextcloud PDF viewer, which allows attackers to execute arbitrary JavaScript within a user's browser by leveraging a crafted PDF file sent to the viewer. This vulnerability affects various versions of the PDF viewer before 22.2.10.33 and multiple subsequent releases, potentially exposing users to various security threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nextcloud 0 < 22.2.10.33
Nextcloud 23 < 23.0.12.29
Nextcloud 24 < 24.0.12.28