Skip to content

Known CVE

ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting

ONLYOFFICE Docs (DocumentServer) <= 8.3.1 contains a reflected XSS caused by improper sanitization of crafted HTTP POST requests via the WOPI protocol, letting attackers inject malicious scripts reflected in HTML response, exploit requires crafted POST requests.

CVE-2025-5301

Medium2025CVSS 6.1CWE-79

cve2025 · onlyoffice · xss · vuln · seclists

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website