Critical severity9.8NVD Advisory· Published Sep 10, 2021· Updated Jun 17, 2026
CVE-2021-40864
CVE-2021-40864
Description
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:onlyoffice:google_translate:*:*:*:*:*:document_server:*:*Range: >=6.1.0,<6.3.0.72
- Range: 6.1.x - 6.3.x before 6.3.0.72
- Range: 6.1.x - 6.3.x before 6.3.0.72
Patches
Vulnerability mechanics
References
2- github.com/ONLYOFFICE/plugin-translator/commit/2206c0179cb97e3b8b290a0ab5719b1f0f54542bnvdPatchThird Party Advisory
- github.com/ONLYOFFICE/plugin-translator/compare/v6.3.0.71...v6.3.0.72nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.