Apache Openoffice
26 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Apache Openoffice, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Apache Openoffice CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 7 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High20
- Medium6
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache Openoffice.
- CVE-2025-64407Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables5.3
- CVE-2025-64406Apache OpenOffice: Possible memory corruption during CSV import4.3
- CVE-2025-64405Apache OpenOffice: Remote documents loaded without prompt via DDE function7.5
- CVE-2025-64404Apache OpenOffice: Remote documents loaded without prompt via background and bullet images7.5
- CVE-2025-64403Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc8.1
- CVE-2025-64402Apache OpenOffice: Remote documents loaded without prompt via OLE objects6.5
- CVE-2025-64401Apache OpenOffice: Remote documents loaded without prompt via IFrame7.5
- CVE-2023-47804Apache OpenOffice: Macro URL arbitrary script execution8.8
- CVE-2022-47502Apache OpenOffice: Macro URL arbitrary script execution7.8
- CVE-2022-38745Apache OpenOffice: Empty entry in Java class path7.8
- CVE-2022-37401Apache OpenOffice Weak Master Keys8.8
- CVE-2022-37400Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password8.8
- CVE-2021-41832Content Manipulation with Certificate Validation Attack7.5
- CVE-2021-41831Timestamp Manipulation with Signature Wrapping5.3
- CVE-2021-41830Double Certificate Attack7.5
Product grouping is registry-driven, with AI assist and human review. How it works