Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-47804

27
FAUCET Score

CVE-2023-47804 affects Apache OpenOffice, allowing arbitrary script execution through specially crafted document links that bypass user approval for internal macro calls. This high-severity vulnerability (CVSS 8.8) can lead to complete compromise of confidentiality, integrity, and availability if a user opens a malicious document. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity landscape.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 4.1.14CPE match
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*
< 4.1.15CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.73%
Probability of exploitation in next 30 days
EPSS Percentile
84.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0273 is in the 83rd percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

denopatch availablevia llm_extracted
Fixed in: 4.1.15
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 4.1.15
View patch
nessuspatch availablevia llm_extracted
Fixed in: 4.1.15
postgresqlpatch availablevia llm_extracted
Fixed in: 4.1.15
View patch

Vendor Advisories (4)

denollm-deno-7a778e5008efbb17

Macro URL arbitrary script execution

postgresqlllm-postgresql-655974ddb4ac820b

Macro URL arbitrary script execution

libreofficellm-libreoffice-31d17afb5ce1f377

Macro URL arbitrary script execution

nessusllm-nessus-e8350604e7f06f6f

Macro URL arbitrary script execution

References

lists.apache.org / thread/ygp59swfcy6g46jf8v9s6qpwmxn8fsvb
Mailing ListVendor Advisory
openoffice.org / security/cves/CVE-2023-47804.html
PatchVendor Advisory
openwall.com / lists/oss-security/2024/01/03/3
Mailing ListThird Party Advisory