Known Vulnerabilities for Document Server by ONLYOFFICE
Listed below are 10 of the newest known vulnerabilities associated with "Document Server" by "ONLYOFFICE".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-107324 json | An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application vali... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-106436 json | The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. T... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-106433 json | Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type whe... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-103957 json | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote... | Not Provided | 2026-10-02 | 2026-10-06 |
| CVE-2026-102244 json | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsens... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-97151 json | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Co... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93421 json | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp_... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-91938 json | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer docum... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-91081 json | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous atta... | Not Provided | 2026-09-14 | 2026-09-20 |
| CVE-2026-89099 json | A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same int... | Not Provided | 2026-09-11 | 2026-09-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Onlyoffice | Document Server | 6.1.1 | |||
| Application | Onlyoffice | Document Server | 6.1.0 | |||
| Application | Onlyoffice | Document Server | 6.0.2 | |||
| Application | Onlyoffice | Document Server | 6.0.1 | |||
| Application | Onlyoffice | Document Server | 6.0.0 | |||
| Application | Onlyoffice | Document Server | 5.6.5 | |||
| Application | Onlyoffice | Document Server | 5.6.4 | |||
| Application | Onlyoffice | Document Server | 5.6.3 | |||
| Application | Onlyoffice | Document Server | 5.6.2 | |||
| Application | Onlyoffice | Document Server | 5.6.1 | |||
| Application | Onlyoffice | Document Server | 5.6.0 | |||
| Application | Onlyoffice | Document Server | 5.5.3 | |||
| Application | Onlyoffice | Document Server | 5.5.1 | |||
| Application | Onlyoffice | Document Server | 5.5.0 | |||
| Application | Onlyoffice | Document Server | 5.4.2 | |||
| Application | Onlyoffice | Document Server | 5.4.1 | |||
| Application | Onlyoffice | Document Server | 5.4.0-2 | |||
| Application | Onlyoffice | Document Server | 5.3.4 | |||
| Application | Onlyoffice | Document Server | 5.3.2 | |||
| Application | Onlyoffice | Document Server | 5.3.1 |