← All CVEs

CVE-2025-5301

medium · 6.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.

6.1
CVSS
62.4%
EPSS (exploit prob.)
99th
EPSS percentile
2025-06-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-5301