Document Foundation, The
First CVE: May 9, 2019Active for: 7 years
44
CVEs Published
More CVEs Published than 54% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Document Foundation, The over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2019
7 years ago
Most Recent CVE
Jun 15, 2026
39 days ago
Top CVEs
All CVEs published by Document Foundation, The as a CNA, regardless of affected vendor or product.
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9851CRITICAL LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launche | Aug 15, 2019 | 9.8 | 82 | NO | YES |
CVE-2019-9848CRITICAL LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also b | Jul 17, 2019 | 9.8 | 48 | NO | NO |
CVE-2026-8357HIGH LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that | Jun 15, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-4430HIGH Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
This issue affects LibreOffice: fr | May 7, 2026 | 7.8 | 31 | NO | NO |
CVE-2024-5261CRITICAL Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification
LibreOfficeKit can be used for accessing LibreOffice fun | Jun 25, 2024 | 9.8 | 31 | NO | NO |
CVE-2026-6040HIGH A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the f | Jun 15, 2026 | 7.3 | 29 | NO | NO |
CVE-2025-1080HIGH LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffi | Mar 4, 2025 | 7.8 | 28 | NO | NO |
CVE-2022-26307HIGH LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the | Jul 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-25631HIGH In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't | May 3, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-6186HIGH Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice sup | Dec 11, 2023 | 8.8 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA44 CVEs
36%
50%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (50.0%)
Network22 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None20 (45.5%)
Unknown0 (0.0%)
Required19 (43.2%)
Privileges Required
Low8 (18.2%)
High0 (0.0%)
None36 (81.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (44 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.3% of CVEs· 92nd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.3% of CVEs· 90th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Document Foundation, The as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Document Foundation, The as a CNA — matched by CVE ID, not by organization name.