Document Foundation, The

First CVE: May 9, 2019Active for: 7 years
44
CVEs Published
More CVEs Published than 54% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Document Foundation, The over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2019
7 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Top CVEs

All CVEs published by Document Foundation, The as a CNA, regardless of affected vendor or product.

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launche
Aug 15, 20199.882NOYES
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also b
Jul 17, 20199.848NONO
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that
Jun 15, 20267.832NONO
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: fr
May 7, 20267.831NONO
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice fun
Jun 25, 20249.831NONO
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the f
Jun 15, 20267.329NONO
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffi
Mar 4, 20257.828NONO
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the
Jul 25, 20228.828NONO
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't
May 3, 20218.828NONO
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice sup
Dec 11, 20238.827NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA44 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local22 (50.0%)
Network22 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None20 (45.5%)
Unknown0 (0.0%)
Required19 (43.2%)
Privileges Required
Low8 (18.2%)
High0 (0.0%)
None36 (81.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.3% of CVEs· 92nd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.3% of CVEs· 90th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Document Foundation, The as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Document Foundation, The as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs