VYPR
Vendor
Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-41030Med0.406.20.00Apr 16, 2026In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
CVE-2026-41034Med0.335.00.00Apr 16, 2026ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.
CVE-2025-689360.000.00Dec 25, 2025ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
CVE-2025-689350.000.00Dec 25, 2025ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.