Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-68935 ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer. Document Server 9.2.1+ Fix from $1,6002025-12-25 MEDIUM 6.1 CVE-2025-68936 ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. Document Server 9.2.1+ Fix from $1,6002025-12-25 MEDIUM 6.7 CVE-2023-46988 Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt… Document Server 8.0.1+ Fix from $1,6002025-04-01 MEDIUM 6.1 CVE-2024-44085 ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked funct… Onlyoffice 8.1.0+ Fix from $1,6002024-09-09 MEDIUM 6.1 CVE-2023-50883 ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possi… Document Server 8.0.1+ Fix from $1,6002024-09-09 CRITICAL 9.8 CVE-2023-30186 A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScri… Document Server after 7.3.2 Fix from $2,3002023-08-14 CRITICAL 9.8 CVE-2023-30187 An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via craft… Document Server after 7.3.2 Fix from $2,3002023-08-14 HIGH 7.5 CVE-2023-30188 Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted Ja… Document Server after 7.3.2 Fix from $1,9502023-08-14 CRITICAL 9.8 CVE-2023-34939EPSS 5% Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ash… Onlyoffice 12.5.2+ Fix from $2,3002023-06-22 HIGH 7.8 CVE-2022-48422 ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current work… Document Server after 7.3.0 Fix from $1,9502023-03-19 MEDIUM 5.4 CVE-2022-47412 Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scri… Workspace after 12.1.0.1760 Fix from $1,6002023-02-07 CRITICAL 9.8 CVE-2021-43445 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONL… Server after 7.0.0.49 Fix from $2,3002023-01-23 HIGH 8.1 CVE-2021-43449 ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and s… Server after 7.0.0.49 Fix from $1,9502023-01-23 HIGH 7.5 CVE-2021-43444 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default U… Server after 7.0.0.49 Fix from $1,9502023-01-23 HIGH 7.5 CVE-2021-43447 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to… Server after 7.0.0.49 Fix from $1,9502023-01-23 MEDIUM 6.1 CVE-2021-43446 ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cr… Server after 7.0.0.49 Fix from $1,6002023-01-23 MEDIUM 5.3 CVE-2021-43448 ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the na… Server after 7.0.0.49 Fix from $1,6002023-01-23 CRITICAL 9.8 CVE-2022-29776EPSS 7% Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/c… Core after 6.1.0.26 Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2022-29777EPSS 7% Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fo… Core after 6.1.0.26 Fix from $2,3002022-06-02 MEDIUM 6.1 CVE-2022-24229 A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaS… Document Server 7.0.0+ Fix from $1,6002022-04-08 CRITICAL 9.8 CVE-2021-40864 The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields. Google Translate 6.3.0.72+ Fix from $2,3002021-09-10 CRITICAL 9.8 CVE-2021-25830EPSS 12% A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion… Document Server after 5.6.4.13 Fix from $2,3002021-03-01 CRITICAL 9.8 CVE-2021-25831EPSS 12% A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of t… Document Server after 5.6.3 Fix from $2,3002021-03-01 CRITICAL 9.8 CVE-2021-25832EPSS 13% A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using th… Document Server after 6.0.0 Fix from $2,3002021-03-01 CRITICAL 9.8 CVE-2021-25833EPSS 44% A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an… Document Server after 5.6.0.21 Fix from $2,3002021-03-01 HIGH 7.5 CVE-2021-25829EPSS 7% An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacke… Document Server after 5.6.3 Fix from $1,9502021-03-01 CRITICAL 9.8 CVE-2021-3199EPSS 8% Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence … Document Server 5.6.3+ Fix from $2,3002021-01-26 CRITICAL 9.8 CVE-2020-11534 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function … Document Server Mitigation only Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11535 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an atta… Document Server Mitigation only Fix from $2,3002020-04-15 CRITICAL 9.8 CVE-2020-11536 An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite … Document Server Mitigation only Fix from $2,3002020-04-15