Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Collabora

First CVE: Jul 21, 2021Active for: 5 yearsTotal CVEs: 7

Collabora develops the Online suite, a web-based collaborative document and office platform that, despite a narrow product focus, sits as a critical component in many organizations' remote work and document-sharing infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through a distinctive pattern of web-application and access-control weaknesses—including cross-site scripting, authorization bypass, OS command injection, and sensitive information disclosure—that reflect the complexity of a browser-based productivity platform handling user content and system integration. Defenders should monitor this vendor's releases closely given the platform's deployment depth; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Collabora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2021
5 years ago
Most Recent CVE
Dec 3, 2025
233 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-66208CRITICAL
Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702
Dec 3, 20259.828NONO
CVE-2021-32744HIGH
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are cur
Jul 21, 20217.523NONO
CVE-2023-31145MEDIUM
Collabora Online is a collaborative online office suite based on LibreOffice technology. This vulnerability report describes a reflected XSS vulnerability with full CSP bypass in N
May 15, 20236.121NONO
CVE-2021-43817MEDIUM
Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attack
Dec 13, 20216.121NONO
CVE-2021-32745MEDIUM
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HT
Jul 21, 20216.120NONO
CVE-2024-45045MEDIUM
Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject J
Aug 29, 20246.118NONO
CVE-2024-25114MEDIUM
Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in a different "ja
Mar 11, 20245.317NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
14%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Collabora.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Collabora — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Collabora's Products

View all 1 CNAs →

Top CWEs