document_server vulnerabilities
CVEs whose affected-version data names the document_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-68936Medium· 6.4ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
▾ Sunlitonlyoffice · document_serverEPSS 0.20%via NVD
CVE-2025-68935Medium· 6.4ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
▾ Sunlitonlyoffice · document_serverEPSS 0.20%via NVD