Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

The Document Foundation — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting The Document Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Document Foundation develops LibreOffice, an open-source office suite widely used for document creation, spreadsheet management, and presentation design across enterprise and personal environments. Its core software processes complex file formats, making it a frequent target for attackers exploiting parsing logic. Historically, common vulnerability classes include remote code execution (RCE) via malformed documents, buffer overflows in legacy components, and cross-site scripting (XSS) within its web-based collaboration tools. While privilege escalation incidents are less frequent, the sheer volume of 26 recorded CVEs highlights persistent risks in handling untrusted input. The organization maintains a transparent security advisory process, addressing critical flaws through regular updates rather than concealing them. Major incidents have primarily involved malicious macro execution or crafted files triggering memory corruption, underscoring the importance of user awareness and timely patching to mitigate these well-documented technical weaknesses in the application’s document processing engine.

Top products by The Document Foundation: LibreOffice
CVE ID Title CVSS Severity Published
CVE-2026-63279 Out of bounds read in PICT image import — LibreOffice CWE-125 5.4 Medium 2026-09-22
CVE-2026-63278 Package URLs can be used to exfiltrate arbitrary INI file values and environment variables — LibreOffice CWE-200 6.7 Medium 2026-09-22
CVE-2026-63276 Stack buffer overflow in CFF to Type 1 font conversion — LibreOffice CWE-787 5.4 Medium 2026-09-22
CVE-2026-63275 Stack buffer overflow in CFF font hint handling — LibreOffice CWE-787 5.4 Medium 2026-09-22
CVE-2026-63274 Heap buffer overflow in PDF import stream handling — LibreOffice CWE-787 5.4 Medium 2026-09-22
CVE-2026-63273 Heap buffer overflow in PDF import encryption handling — LibreOffice CWE-787 5.4 Medium 2026-09-22
CVE-2026-63272 Heap buffer overflow in WMF text record import — LibreOffice CWE-787 5.4 Medium 2026-09-22
CVE-2026-8358 Heap buffer overflow in spreadsheet tracked-changes import — LibreOffice CWE-843 - - 2026-06-15
CVE-2026-8357 Heap buffer overflow in Calc formula compilation — LibreOffice CWE-787 5.4 Medium 2026-06-15
CVE-2026-8356 Stack buffer overflow in PPT presentation import — LibreOffice CWE-787 - - 2026-06-15
CVE-2026-6047 Heap buffer overflow in OOXML text box element import — LibreOffice CWE-787 - - 2026-06-15
CVE-2026-6045 Heap buffer overflow in EMF+ gradient brush import — LibreOffice CWE-787 5.4 Medium 2026-06-15
CVE-2026-6040 Heap use-after-free in ODF number-format blank-width parsing — LibreOffice CWE-416 5.4 Medium 2026-06-15
CVE-2026-6039 Heap buffer overflow in DXF polyline import — LibreOffice CWE-787 - - 2026-06-15
CVE-2026-4430 Heap Buffer Overflow in AgileEngine — LibreOffice CWE-787 7.8AI High AI 2026-05-07
CVE-2025-14714 TCC Bypass via Inherited Permissions in Bundled Interpreter — LibreOffice CWE-288 9.8AI Critical AI 2025-12-15
CVE-2025-2866 PDF signature forgery with adbe.pkcs7.sha1 SubFilter — LibreOffice CWE-347 6.5 - 2025-04-27
CVE-2021-25635 Content Manipulation with Certificate Validation Attack — LibreOffice CWE-295 7.5 - 2025-03-21
CVE-2025-1080 Macro URL arbitrary script execution — LibreOffice CWE-20 8.8 - 2025-03-04
CVE-2025-0514 Executable hyperlink Windows path targets executed unconditionally on activation — LibreOffice CWE-20 6.5 - 2025-02-25
CVE-2024-12426 URL fetching can be used to exfiltrate arbitrary INI file values and environment variables — LibreOffice CWE-200 6.5 - 2025-01-07
CVE-2024-12425 Path traversal leading to arbitrary .ttf file write — LibreOffice CWE-22 6.2 - 2025-01-07
CVE-2024-7788 Signatures in "repair mode" should not be trusted — LibreOffice CWE-347 7.8 High 2024-09-17
CVE-2024-6472 Ability to trust not validated macro signatures removed in high security mode — LibreOffice CWE-295 7.8 High 2024-08-05
CVE-2024-5261 TLS certificate are not properly verified when utilizing LibreOfficeKit — LibreOffice CWE-295 9.1AI Critical AI 2024-06-25
CVE-2024-3044 Graphic on-click binding allows unchecked script execution — LibreOffice CWE-356 7.1 - 2024-05-14
CVE-2023-6186 Link targets allow arbitrary script execution — LibreOffice 8.3 High 2023-12-11
CVE-2023-6185 Improper input validation enabling arbitrary Gstreamer pipeline injection — LibreOffice 8.3 High 2023-12-11
CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing — LibreOffice CWE-129 8.8 - 2023-05-25
CVE-2023-2255 Remote documents loaded without prompt via IFrame — LibreOffice CWE-264 5.3 - 2023-05-25

This page lists every published CVE security advisory associated with The Document Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.