Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
onlyoffice server vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-29776
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
9.8
CVSSv3
CVE-2022-29777
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
8.1
CVSSv3
CVE-2021-43449
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.
Onlyoffice Server
9.8
CVSSv3
CVE-2021-43445
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
Onlyoffice Server
7.5
CVSSv3
CVE-2021-43444
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
Onlyoffice Server
6.1
CVSSv3
CVE-2021-43446
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.
Onlyoffice Server
7.5
CVSSv3
CVE-2021-43447
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows malicious users to edit documents without authentication.
Onlyoffice Server
5.3
CVSSv3
CVE-2021-43448
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an malicious user to spoof the names of users who interact with a document, if the document id is known.
Onlyoffice Server
9.8
CVSSv3
CVE-2021-3199
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server prior to 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Onlyoffice Document Server
1 Github repository
7.8
CVSSv3
CVE-2022-48422
ONLYOFFICE Docs up to and including 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
Onlyoffice Document Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »