Security Advisory

CVE-2025-68917

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-24 20:19:25
Last updated 2025-12-24 20:38:16
Assigner mitre
State PUBLISHED

Description

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.