{"api_version":"1","generated_at":"2026-07-23T19:43:48+00:00","cve":"CVE-2016-7419","urls":{"html":"https://cve.report/CVE-2016-7419","api":"https://cve.report/api/cve/CVE-2016-7419.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-7419","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-7419"},"summary":{"title":"CVE-2016-7419","description":"Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.","state":"PUBLISHED","assigner":"mitre","published_at":"2016-09-17 21:59:11","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/92373","name":"http://www.securityfocus.com/bid/92373","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ownCloud Gallery Application 'share.js' HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc","name":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Add more escaping · nextcloud/gallery@6933d27 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001","name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"advisory – Nextcloud","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011","name":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Advisory | ownCloud.org","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://hackerone.com/reports/145355","name":"https://hackerone.com/reports/145355","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"#145355 Stored XSS on Share-popup of a directory's Gallery-view - HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-7419","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7419","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"7419","vulnerable":"1","versionEndIncluding":"9.0.51","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nextcloud","cpe5":"nextcloud_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7419","vulnerable":"1","versionEndIncluding":"9.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"owncloud","cpe5":"owncloud","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"7419","cve":"CVE-2016-7419","epss":"0.002000000","percentile":"0.417440000","score_date":"2026-05-06","updated_at":"2026-05-07 00:10:58"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:57:47.535Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"92373","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/92373"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://hackerone.com/reports/145355"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-07-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-25T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"92373","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/92373"},{"tags":["x_refsource_CONFIRM"],"url":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011"},{"tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/145355"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc"},{"tags":["x_refsource_CONFIRM"],"url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-7419","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"92373","refsource":"BID","url":"http://www.securityfocus.com/bid/92373"},{"name":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011","refsource":"CONFIRM","url":"https://owncloud.org/security/advisory/?id=oc-sa-2016-011"},{"name":"https://hackerone.com/reports/145355","refsource":"MISC","url":"https://hackerone.com/reports/145355"},{"name":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc","refsource":"CONFIRM","url":"https://github.com/nextcloud/gallery/commit/6933d27afe518967bd1b60e6a7eacd88288929fc"},{"name":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001","refsource":"CONFIRM","url":"https://nextcloud.com/security/advisory/?id=nc-sa-2016-001"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2016-7419","datePublished":"2016-09-17T21:00:00.000Z","dateReserved":"2016-09-09T00:00:00.000Z","dateUpdated":"2024-08-06T01:57:47.535Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-09-17 21:59:11","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0.51","matchCriteriaId":"B7C653C0-53CE-4CC6-99C5-DB1AC94D539B"},{"vulnerable":true,"criteria":"cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0.3","matchCriteriaId":"AC698542-23B9-4101-BD01-10D2FB0870E9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"7419","Ordinal":"1","Title":"CVE-2016-7419","CVE":"CVE-2016-7419","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"7419","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.","Type":"Description","Title":"CVE-2016-7419"},{"CveYear":"2016","CveId":"7419","Ordinal":"2","NoteData":"2016-09-17","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"7419","Ordinal":"3","NoteData":"2016-11-25","Type":"Other","Title":"Modified"}]}}}