Browse all 27 CVE security advisories affecting The Document Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.
The Document Foundation develops LibreOffice, an open-source office suite widely used for document creation, spreadsheet management, and presentation design across enterprise and personal environments. Its core software processes complex file formats, making it a frequent target for attackers exploiting parsing logic. Historically, common vulnerability classes include remote code execution (RCE) via malformed documents, buffer overflows in legacy components, and cross-site scripting (XSS) within its web-based collaboration tools. While privilege escalation incidents are less frequent, the sheer volume of 26 recorded CVEs highlights persistent risks in handling untrusted input. The organization maintains a transparent security advisory process, addressing critical flaws through regular updates rather than concealing them. Major incidents have primarily involved malicious macro execution or crafted files triggering memory corruption, underscoring the importance of user awareness and timely patching to mitigate these well-documented technical weaknesses in the application’s document processing engine.
This page lists every published CVE security advisory associated with The Document Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.