Collabora develops the Online suite, a web-based collaborative document and office platform that, despite a narrow product focus, sits as a critical component in many organizations' remote work and document-sharing infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through a distinctive pattern of web-application and access-control weaknesses—including cross-site scripting, authorization bypass, OS command injection, and sensitive information disclosure—that reflect the complexity of a browser-based productivity platform handling user content and system integration. Defenders should monitor this vendor's releases closely given the platform's deployment depth; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collabora over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66208CRITICAL Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702 | Dec 3, 2025 | 9.8 | 28 | NO | NO |
CVE-2021-32744HIGH Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are cur | Jul 21, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-31145MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. This vulnerability report describes a reflected XSS vulnerability with full CSP bypass in N | May 15, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-43817MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attack | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-32745MEDIUM Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HT | Jul 21, 2021 | 6.1 | 20 | NO | NO |
CVE-2024-45045MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject J | Aug 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-25114MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in a different "ja | Mar 11, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collabora.
Media articles that mention a CVE ID that affects a product developed by Collabora — matched by CVE ID, not by vendor name.