Known Vulnerabilities for OnlyOffice by Ascensio System SIA
Listed below are 4 of the newest known vulnerabilities associated with "OnlyOffice" by "Ascensio System SIA".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-38587 json | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists ... | Not Provided | 2026-05-26 | 2026-05-26 |
| CVE-2023-30188 json | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial o... | Not Provided | 2023-08-14 | 2026-07-09 |
| CVE-2023-30187 json | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run ... | Not Provided | 2023-08-14 | 2026-07-09 |
| CVE-2023-30186 json | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary c... | Not Provided | 2023-08-14 | 2026-07-09 |