« Back to list

Onlyoffice

Onlyoffice Server: vulnerabilities and CVEs

Onlyoffice Server has 6 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months0
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-43449High (8.1)1.2%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.
CVE-2021-43448Medium (5.3)1.0%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.
CVE-2021-43447High (7.5)1.3%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
CVE-2021-43446Medium (6.1)0.82%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malicious cross site scripting payloads to be used.
CVE-2021-43445Critical (9.8)1.7%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a…
CVE-2021-43444High (7.5)1.2%—Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

Other products by Onlyoffice