Skip to content
COOEY

FAIL › dossier

onlyoffice

VENDOR

· dossier confidence 20%

ONLYOFFICE is a Ukrainian software vendor whose DocumentServer product suffered two critical RCE vulnerabilities in 2023, revealing significant risks in its JavaScript processing and memory management.

PROFILE
Categorysoftware vendorWhat they doONLYOFFICE provides open-source office productivity software including document editors, spreadsheets, and presentations. Websitehttps://www.onlyoffice.com ↗
SECURITY POSTURE

The company has a documented history of critical remote code execution vulnerabilities in its DocumentServer product, indicating potential gaps in input validation and memory safety for JavaScript processing.

Notable failures
  • CVE-2023-30186 (RCE via use-after-free)
  • CVE-2023-30187 (RCE via out-of-bounds memory access)
Patterns: critical RCEs in DocumentServer via crafted JavaScript files
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2023-08-14 CVE-2023-30186 critical A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
2023-08-14 CVE-2023-30187 critical An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Open questions: What is the exact founding year of ONLYOFFICE? · What is the precise headquarters location of ONLYOFFICE? · What is the current employee count of ONLYOFFICE?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 03:58:38.077783+00:00