{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "fixed": "0.19.14"
              },
              {
                "introduced": "0.20.0"
              },
              {
                "fixed": "0.20.10"
              },
              {
                "introduced": "0.21.0"
              },
              {
                "fixed": "0.21.3"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "e7fbdaa16c2c2a17e8a59bd985495114468bacf8"
            },
            {
              "introduced": "e6993c92e22887535d39da11724f1338dd1a36cf"
            },
            {
              "fixed": "e912dd896eec91dbeba414095e47ba6d5b313abe"
            },
            {
              "introduced": "847abed0f9b42f5b8751ef14e59c5b75137d6ca6"
            },
            {
              "fixed": "08a33ff0fac80137ba14ad4403129d462c7a5723"
            },
            {
              "fixed": "dbb97a83ccb342c839a54f088aa19b8ba6844b0e"
            }
          ],
          "repo": "https://github.com/nextcloud/circles",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Circles application is upgraded to 0.21.3, 0.20.10 or 0.19.14 to resolve this issue. As a workaround users may use a browser that has support for Content-Security-Policy. A notable exemption is Internet Explorer which does not support CSP properly.",
  "id": "CVE-2021-32782",
  "modified": "2026-03-13T21:55:10.083539389Z",
  "published": "2021-09-07T20:15:07.603Z",
  "references": [
    {
      "type": "REPORT",
      "url": "https://hackerone.com/reports/1217606"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/circles/commit/dbb97a83ccb342c839a54f088aa19b8ba6844b0e"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hgpq-28gj-jrj9"
    }
  ],
  "related": [
    "GHSA-hgpq-28gj-jrj9"
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}