Medium severity6.4OSV Advisory· Published Dec 25, 2025· Updated Jun 17, 2026
CVE-2025-68935
CVE-2025-68935
Description
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3ONLYOFFICE-DocumentServer-3.0.0, ONLYOFFICE-DocumentServer-4.0.0-9, ONLYOFFICE-DocumentServer-4.0.1-34, …+ 1 more
- (no CPE)range: ONLYOFFICE-DocumentServer-3.0.0, ONLYOFFICE-DocumentServer-4.0.0-9, ONLYOFFICE-DocumentServer-4.0.1-34, …
- (no CPE)range: <9.2.1
Patches
Vulnerability mechanics
References
1- github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.mdnvdRelease Notes
News mentions
0No linked articles in our index yet.