CVE-2025-68936
- EPSS 0.01%
- Veröffentlicht 25.12.2025 20:15:42
- Zuletzt bearbeitet 02.01.2026 19:36:52
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
CVE-2025-68935
- EPSS 0.01%
- Veröffentlicht 25.12.2025 20:15:42
- Zuletzt bearbeitet 02.01.2026 19:37:26
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
CVE-2025-68917
- EPSS 0.04%
- Veröffentlicht 24.12.2025 20:19:25
- Zuletzt bearbeitet 29.12.2025 15:58:13
ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
CVE-2025-5301
- EPSS 5.35%
- Veröffentlicht 12.06.2025 08:15:23
- Zuletzt bearbeitet 18.06.2025 05:15:50
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which a...
CVE-2023-46988
- EPSS 0.31%
- Veröffentlicht 01.04.2025 22:15:20
- Zuletzt bearbeitet 01.10.2025 10:53:46
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and pot...
CVE-2023-50883
- EPSS 0.41%
- Veröffentlicht 09.09.2024 20:15:03
- Zuletzt bearbeitet 20.09.2024 15:18:06
ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an...
CVE-2023-30188
- EPSS 0.85%
- Veröffentlicht 14.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:52
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
CVE-2023-30187
- EPSS 1.88%
- Veröffentlicht 14.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:52
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
CVE-2023-30186
- EPSS 0.93%
- Veröffentlicht 14.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:52
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
CVE-2022-48422
- EPSS 0.03%
- Veröffentlicht 19.03.2023 01:15:39
- Zuletzt bearbeitet 27.02.2025 17:15:13
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.