Vulnerabilidades em ONLYOFFICE
8 resultadosAnálise Vexday
O ONLYOFFICE apresenta um perfil de risco baixo com apenas 4 vulnerabilidades catalogadas, nenhuma delas explorada ativamente ou classificada como crítica. A fraqueza dominante identificada é Cross-Site Scripting (CWE-79), um vetor de impacto moderado, e não há registros de divulgações recentes, sugerindo que o risco permanece estável.
CVE-2025-5301MEDIUMReflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer)EPSS 62.4%CVE-2025-6380CRITICALONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback FunctionEPSS 0.7%CVE-2022-47412MEDIUMONLYOFFICE Workspace Search Stored XSSEPSS 0.6%CVE-2024-11750MEDIUMONLYOFFICE DocSpace <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-11450MEDIUMONLYOFFICE Docs <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-68936MEDIUMONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.EPSS 0.2%CVE-2025-68935MEDIUMONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.EPSS 0.2%CVE-2025-68917MEDIUMONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.EPSS 0.2%