CVE-2025-68935: ONLYOFFICE Document Server

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

Affected products

  • ONLYOFFICE Document Server: before 9.2.1 (fixed in 9.2.1)

Published 2025-12-25. Last modified 2026-10-07.