CVE-2025-68917: XSS
Published Dec 24, 2025
·Updated
ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
Affected Software
1 affected component
Onlyoffice ONLYOFFICE Docs<9.2.1
Event History
Dec 24, 2025
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68917?
The severity of CVE-2025-68917 is classified as medium, indicating a moderate risk of exploitation.
2
How do I fix CVE-2025-68917?
To fix CVE-2025-68917, upgrade ONLYOFFICE Docs to version 9.2.1 or later.
3
What is the impact of CVE-2025-68917?
The impact of CVE-2025-68917 allows attackers to execute cross-site scripting (XSS) in the comment editing form.
4
Which versions of ONLYOFFICE Docs are affected by CVE-2025-68917?
CVE-2025-68917 affects ONLYOFFICE Docs versions prior to 9.2.1.
5
Is there a workaround for CVE-2025-68917?
There are no specific workarounds for CVE-2025-68917; upgrading to the secure version is the recommended course of action.