VYPR
Vendor

Collaboraoffice

Products
4
CVEs
5
Across products
5
Status
Private

Products

4

Recent CVEs

5
  • CVE-2023-34088HigMay 31, 2023
    risk 0.57cvss 8.7epss 0.00

    Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an…

  • CVE-2021-25630HigFeb 23, 2021
    risk 0.51cvss 7.8epss 0.00

    "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of…

  • CVE-2023-49788HigDec 8, 2023
    risk 0.47cvss 7.2epss 0.01

    Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versions of the richdocumentscode app can be…

  • CVE-2023-49782HigDec 8, 2023
    risk 0.46cvss 7.1epss 0.00

    Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to attack via proxy.php. The bug was fixed in Collabora Online - Built-in CODE Server…

  • CVE-2020-12432MedJul 21, 2020
    risk 0.40cvss 6.1epss 0.01

    The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The…