CVE-2023-34939: ONLYOFFICE

Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.

Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.

Affected products

  • ONLYOFFICE ONLYOFFICE: before 12.5.2 (fixed in 12.5.2)

Published 2023-06-22. Last modified 2026-06-17.