CVE Tools

Onlyoffice

6 CVEs tracked since 2023. Since Jan 2023, none of them reached CISA KEV.

Onlyoffice CVEs per month

Jan 2023 to Jan 2023. Point at a month, or focus the strip and use the arrow keys.
Onlyoffice CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0160

Products

The products that kept showing up in Onlyoffice's monthly top three, with their CVEs summed over those months.

  1. Server61 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Onlyoffice.

  1. CVE-2025-68936ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.6.4
  2. CVE-2025-68935ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.6.4
  3. CVE-2025-68917ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.6.4
  4. CVE-2025-6380ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback Function9.8
  5. CVE-2025-5301Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer)6.1
  6. CVE-2023-46988Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, lead...6.7
  7. CVE-2024-11750ONLYOFFICE DocSpace <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  8. CVE-2024-11450ONLYOFFICE Docs <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  9. CVE-2024-44085ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this is...6.1
  10. CVE-2023-50883ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the F...6.1
  11. CVE-2023-30186A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.9.8
  12. CVE-2023-30188Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.7.5
  13. CVE-2023-30187An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.9.8
  14. CVE-2023-34939Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.9.8
  15. CVE-2022-48422ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in whi...7.8

The record

Peak rank
#93 in Jan 2023
Busiest month shown
Jan 2023, 6 CVEs
Months with a KEV entry
0 since Jan 2023
Monthly snapshots
1 since 2023
Onlyoffice's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store