Nextcloud Contacts vulnerable to Stored XSS in contacts app via organisation and title field
CVE-2025-66554

3.5LOW

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
5 December 2025

What is CVE-2025-66554?

Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. Prior to 5.5.4, 6.0.6, and 7.2.5, a malicious user was able to modify their organisation and title field to load additional CSS files. Javascript and other options were correctly blocked by the content security policy of the Nextcloud Server code. This vulnerability is fixed in 5.5.4, 6.0.6, and 7.2.5.

Affected Version(s)

security-advisories >= 7.0.0-alpha.1, < 7.2.5 < 7.0.0-alpha.1, 7.2.5

security-advisories >= 6.0.0-alpha1, < 6.0.6 < 6.0.0-alpha1, 6.0.6

security-advisories < 5.5.4 < 5.5.4

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66554 : Vulnerability in Contacts App for Nextcloud Allows Malicious CSS Manipulation