ZeroHour

CVE-2025-68935

CVSS 3.1
6.1 medium
EPSS
<1%p10
Published
()
Modified
Description

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

Vendors
onlyoffice
Products
document server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.