Known Vulnerabilities for Extract by Nextcloud

Listed below are 1 of the newest known vulnerabilities associated with "Extract" by "Nextcloud".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-41320 json Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially cr... Not Provided 2026-04-21 2026-04-22
CVE-2026-40584 json RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affec... Not Provided 2026-04-21 2026-04-21
CVE-2026-40344 json MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T0... Not Provided 2026-04-22 2026-04-22
CVE-2026-40313 json PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPA... Not Provided 2026-04-14 2026-04-14
CVE-2026-40308 json My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX end... Not Provided 2026-04-16 2026-04-17
CVE-2026-40285 json WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/mem... Not Provided 2026-04-17 2026-04-20
CVE-2026-40157 json PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using ... Not Provided 2026-04-10 2026-04-14
CVE-2026-39857 json ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass ... Not Provided 2026-04-15 2026-04-16
CVE-2026-39412 json LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter... Not Provided 2026-04-08 2026-04-09
CVE-2026-39334 json ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoin... Not Provided 2026-04-07 2026-04-07

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationNextcloudExtract1.2.0
ApplicationNextcloudExtract1.1.1
ApplicationNextcloudExtract1.1.0
ApplicationNextcloudExtract1.0.0
ApplicationNextcloudExtract0.0.4
ApplicationNextcloudExtract0.0.3
ApplicationNextcloudExtract0.0.2
ApplicationNextcloudExtract0.0.1
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report