onlyoffice security advisories
5 threat alerts tracking vulnerabilities and security advisories that affect onlyoffice products.
Vulnios monitors onlyoffice CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent onlyoffice security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-3199 — onlyoffice — document_server
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
criticalCVE-2021-3199Critical Vulnerability: CVE-2020-11534 — onlyoffice — document_server
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function to pass parameters to a binary (such as curl or wge
criticalCVE-2020-11534Critical Vulnerability: CVE-2020-11537 — onlyoffice — document_server
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
criticalCVE-2020-11537Critical Vulnerability: CVE-2020-11535 — onlyoffice — document_server
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to r
criticalCVE-2020-11535Critical Vulnerability: CVE-2020-11536 — onlyoffice — document_server
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite a binary and remotely execute code on a victim's se
criticalCVE-2020-11536
Track onlyoffice exposure across your environment
Vulnios automatically cross-references your asset inventory against new onlyoffice CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan