Collabora Office maintains a focused portfolio of document-editing and office-productivity products, primarily Collabora Online and its associated development editions, which serve as collaborative alternatives to mainstream office suites in managed environments. Vulnerabilities affecting this vendor cluster around web-application and access-control weaknesses, including cross-site scripting, path traversal, improper privilege management, and trust boundary violations, reflecting the challenges inherent to browser-based document editing and multi-user file access. Treat this as a compact vendor profile tied to specific deployment contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collaboraoffice over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25630HIGH "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the " | Feb 23, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-48314MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with Collabora Online Built-in CODE Server app can be vulnerable to atta | Dec 1, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-29182MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerability was found in Collabora Online. An attacker could create a | Apr 4, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-49788HIGH Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocume | Dec 8, 2023 | 7.2 | 18 | NO | NO |
CVE-2023-49782MEDIUM Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to | Dec 8, 2023 | 6.1 | 18 | NO | NO |
CVE-2020-12432MEDIUM The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control | Jul 21, 2020 | 6.1 | 17 | NO | NO |
CVE-2023-34088MEDIUM Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and | May 31, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collaboraoffice.
Media articles that mention a CVE ID that affects a product developed by Collaboraoffice — matched by CVE ID, not by vendor name.