CVE-2025-68935
EUVD-2025-20539325.12.2025, 20:15
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| onlyoffice | document_server | 𝑥 < 9.2.1 |
𝑥
= Vulnerable software versions