CVE-2025-68935

Publication date

2025-12-25 20:05:48

Family

mitre

State

PUBLISHED

Description

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.