onlyoffice has 2 CVEs on record. The median CVSS is 6.4 (medium).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- document_server 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
onlyoffice vulnerabilities
CVEs affecting onlyoffice, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2025-68936Medium· 6.4ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
▾ Sunlitonlyoffice · document_serverEPSS 0.20%via NVD
CVE-2025-68935Medium· 6.4ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
▾ Sunlitonlyoffice · document_serverEPSS 0.20%via NVD