VYPR

Documentserver

by ONLYOFFICE

Source repositories

CVEs (25)

  • CVE-2022-24229MedApr 8, 2022
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.

  • CVE-2026-41034MedApr 16, 2026
    risk 0.26cvss 5.0epss 0.00

    ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.

  • CVE-2022-29777CriJun 2, 2022
    risk 0.01cvss 9.8epss 0.07

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

  • CVE-2022-29776CriJun 2, 2022
    risk 0.01cvss 9.8epss 0.07

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.

  • CVE-2021-40864CriSep 10, 2021
    risk 0.00cvss 9.8epss 0.02

    The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

Page 2 of 2