CVE-2023-34939: ONLYOFFICE
Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
Affected products
- ONLYOFFICE ONLYOFFICE: before 12.5.2 (fixed in 12.5.2)
Published 2023-06-22. Last modified 2026-06-17.