The Document Foundation has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-787 (5) and CWE-125 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Worst active — by depth score
CVE-2026-63278Medium· 6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links37CVE-2026-63279Medium· 5.4LibreOffice can import PICT images, which may be embedded in documents30CVE-2026-63276Medium· 5.4LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents30CVE-2026-63275Medium· 5.4LibreOffice can read CFF fonts, which may be embedded in documents30CVE-2026-63274Medium· 5.4LibreOffice Draw can import PDF documents30
The Document Foundation vulnerabilities
CVEs affecting The Document Foundation, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-63275Medium· 5.4LibreOffice can read CFF fonts, which may be embedded in documents
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…
CVE-2026-63272Medium· 5.4LibreOffice can import WMF graphics, which may be embedded in documents
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…
CVE-2026-63278Medium· 6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…
CVE-2026-63276Medium· 5.4LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators we…
CVE-2026-63273Medium· 5.4LibreOffice Draw can import PDF documents
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size ke…
CVE-2026-63279Medium· 5.4LibreOffice can import PICT images, which may be embedded in documents
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the…
CVE-2026-63274Medium· 5.4LibreOffice Draw can import PDF documents
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…