CVE-2022-47412: ONLYOFFICE Workspace

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.

Affected products

  • ONLYOFFICE Workspace: up to and including 12.1.0.1760

Published 2023-02-07. Last modified 2026-06-17.