Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Onlyoffice

First CVE: Apr 15, 2020Active for: 6 yearsTotal CVEs: 32
44.4
VTI Score
High

Onlyoffice develops a suite of document editing and collaboration server products that integrate productivity functionality into web platforms and self-hosted deployments, positioning them across enterprise and cloud-based document workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, with the exposure concentrating in the Document Server and core editing components and recurring through application-layer weakness classes including cross-site scripting, path traversal, out-of-bounds writes, and improper input validation. These patterns reflect the complexity of parsing multiple document formats, rendering content securely, and validating user-supplied file paths and parameters in a web-accessible context. Defenders should treat Onlyoffice advisories as high-priority where the product is exposed to untrusted document sources or internet-facing deployments, and should prioritize patching to limit the attack surface of document conversion and preview functionality. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Onlyoffice over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2020
6 years ago
Most Recent CVE
Dec 25, 2025
211 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25833CRITICAL
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request d
Mar 1, 20219.853NONO
CVE-2021-25832CRITICAL
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker i
Mar 1, 20219.837NONO
CVE-2022-29777CRITICAL
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFile
Jun 2, 20229.835NONO
CVE-2021-25831CRITICAL
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into
Mar 1, 20219.835NONO
CVE-2021-25830CRITICAL
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT
Mar 1, 20219.835NONO
CVE-2022-29776CRITICAL
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
Jun 2, 20229.834NONO
CVE-2021-3199CRITICAL
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Jan 26, 20219.833NONO
CVE-2021-40864CRITICAL
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
Sep 10, 20219.831NONO
CVE-2023-30186CRITICAL
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Aug 14, 20239.830NONO
CVE-2023-34939CRITICAL
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
Jun 22, 20239.830NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
31%
19%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (6.3%)
Network30 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (93.8%)
High2 (6.3%)
Unknown0 (0.0%)
User Interaction
None22 (68.8%)
Unknown0 (0.0%)
Required10 (31.3%)
Privileges Required
Low2 (6.3%)
High0 (0.0%)
None30 (93.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Onlyoffice.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Onlyoffice — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Onlyoffice's Products

View all 2 CNAs →

Top CWEs