LibreOffice is a widely deployed open-source office suite that spans document editing, spreadsheet, and presentation functionality across desktop and server environments, positioning it as a prominent target for document-handling exploits. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, driven by the software's need to parse and render diverse file formats from untrusted sources. The exposure recurs through input-validation weaknesses, out-of-bounds writes, memory-buffer boundary violations, and certificate-validation issues—characteristic flaws in document processors handling complex legacy formats and embedded content. Defenders should treat LibreOffice advisories as priority, particularly in environments where users open documents from external sources or where the suite is deployed server-side for document conversion. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libreoffice over time
Signals from CVEs in this vendor scope (71 CVEs).
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16858CRITICAL It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document | Mar 25, 2019 | 9.8 | 84 | NO | YES |
CVE-2019-9851CRITICAL LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launche | Aug 15, 2019 | 9.8 | 82 | NO | YES |
CVE-2018-10583HIGH An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a maliciou | May 1, 2018 | 7.5 | 78 | NO | YES |
CVE-2018-6871CRITICAL LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function. | Feb 9, 2018 | 9.8 | 54 | NO | YES |
CVE-2023-1183MEDIUM A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written | Jul 10, 2023 | 5.5 | 52 | NO | NO |
CVE-2019-9848CRITICAL LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also b | Jul 17, 2019 | 9.8 | 48 | NO | NO |
CVE-2017-7870CRITICAL LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx. | Apr 14, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-7882CRITICAL LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx. | Apr 15, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-7856CRITICAL LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx | Apr 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2026-4430HIGH Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
This issue affects LibreOffice: fr | May 7, 2026 | 7.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (71 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libreoffice.
Media articles that mention a CVE ID that affects a product developed by Libreoffice — matched by CVE ID, not by vendor name.