Browse all 8 CVE security advisories affecting OnlyOffice. AI-powered Chinese analysis, POCs, and references for each vulnerability.
ONLYOFFICE is a collaborative platform offering document editing, management, and office suite functionality. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and access control flaws. The platform has faced security concerns, with eight CVEs recorded to date, highlighting risks in areas like API endpoints and document processing. While providing comprehensive collaboration tools, security researchers have identified potential weaknesses in authentication mechanisms and file handling. Organizations implementing ONLYOFFICE should prioritize regular updates and security hardening to mitigate these risks, as the platform's broad functionality increases its attack surface.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-47412 | ONLYOFFICE Workspace Search Stored XSS — WorkspaceCWE-79 | 5.4 | - | 2023-02-07 |
This page lists every published CVE security advisory associated with OnlyOffice. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.