Onlyoffice

    Dashboard / Vendors

    Products: 9
    Vulnerabilities: 38
    Known Exploited: 0
    16
    Critical Level Threats
    6
    High Level Threats
    14
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-84282

    A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin (version 9.12)

    Last Modified: Sep 11, 2026
    Published: Sep 08, 2026

    CVE-2026-38587

    An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and profile information, which should only be accessible to administrators.

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-41034

    Untrusted Pointer Dereference in ONLYOFFICE DocumentServer XLS Processing Causes Information Leak and ASLR Bypass

    Last Modified: Apr 17, 2026
    Published: Apr 16, 2026

    CVE-2025-68936

    ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

    Last Modified: Jan 02, 2026
    Published: Dec 25, 2025

    CVE-2025-68935

    ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

    Last Modified: Jan 02, 2026
    Published: Dec 25, 2025
    Items Per Page
    Onlyoffice Vulnerabilities & Security CVEs | CVE-DB