Onlyoffice develops a suite of document editing and collaboration server products that integrate productivity functionality into web platforms and self-hosted deployments, positioning them across enterprise and cloud-based document workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, with the exposure concentrating in the Document Server and core editing components and recurring through application-layer weakness classes including cross-site scripting, path traversal, out-of-bounds writes, and improper input validation. These patterns reflect the complexity of parsing multiple document formats, rendering content securely, and validating user-supplied file paths and parameters in a web-accessible context. Defenders should treat Onlyoffice advisories as high-priority where the product is exposed to untrusted document sources or internet-facing deployments, and should prioritize patching to limit the attack surface of document conversion and preview functionality. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onlyoffice over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25833CRITICAL A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request d | Mar 1, 2021 | 9.8 | 53 | NO | NO |
CVE-2021-25832CRITICAL A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker i | Mar 1, 2021 | 9.8 | 37 | NO | NO |
CVE-2022-29777CRITICAL Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFile | Jun 2, 2022 | 9.8 | 35 | NO | NO |
CVE-2021-25831CRITICAL A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into | Mar 1, 2021 | 9.8 | 35 | NO | NO |
CVE-2021-25830CRITICAL A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT | Mar 1, 2021 | 9.8 | 35 | NO | NO |
CVE-2022-29776CRITICAL Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp. | Jun 2, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-3199CRITICAL Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter. | Jan 26, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-40864CRITICAL The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields. | Sep 10, 2021 | 9.8 | 31 | NO | NO |
CVE-2023-30186CRITICAL A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | Aug 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-34939CRITICAL Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx. | Jun 22, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onlyoffice.
Media articles that mention a CVE ID that affects a product developed by Onlyoffice — matched by CVE ID, not by vendor name.