CVE-2023-30187: ONLYOFFICE Document Server

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

Affected products

  • ONLYOFFICE Document Server: from 4.0.3, up to and including 7.3.2

Published 2023-08-14. Last modified 2026-07-09.