📦 Libreoffice

by Libreoffice

🔍 What is Libreoffice?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-5261

CRITICAL CVSS 9.8 Jun 25, 2024

LibreOfficeKit mode in LibreOffice versions before 24.2.4 disables TLS certificate verification when fetching remote resources via curl, allowing man-in-the-middle attacks. This affects third-party ap...

CVE-2025-1080

HIGH CVSS 7.8 Mar 4, 2025

This vulnerability in LibreOffice allows attackers to craft malicious links using the 'vnd.libreoffice.command' URI scheme that can execute internal macros with arbitrary arguments when clicked in a b...

CVE-2025-0514

HIGH CVSS 7.8 Feb 25, 2025

This vulnerability in LibreOffice allows attackers to execute arbitrary Windows executables through malicious hyperlinks. When a user clicks on a specially crafted hyperlink in a document, the executa...

CVE-2024-6472

HIGH CVSS 7.8 Aug 5, 2024

This vulnerability in LibreOffice's certificate validation UI could allow users to inadvertently run malicious signed macros when certificate verification fails. The interface previously didn't clearl...

CVE-2023-6186

HIGH CVSS 8.3 Dec 11, 2023

This vulnerability in LibreOffice allows attackers to execute built-in macros without user warnings by exploiting insufficient permission validation in hyperlinks. Users who open malicious documents i...

CVE-2022-26305

HIGH CVSS 7.5 Jul 25, 2022

LibreOffice improperly validates macro signatures by only checking certificate serial numbers and issuer strings, not the actual cryptographic signature. Attackers can create fake certificates matchin...

CVE-2022-26307

HIGH CVSS 8.8 Jul 25, 2022

A flaw in LibreOffice's password storage system weakens encryption from 128-bit to 43-bit entropy, making stored web connection passwords vulnerable to brute-force attacks if an attacker gains access ...

CVE-2021-25636

HIGH CVSS 7.5 Feb 24, 2022

This vulnerability allows an attacker to create a digitally signed LibreOffice document that appears valid but actually uses a different key for verification than what's displayed to the user. Attacke...

CVE-2021-25634

HIGH CVSS 7.5 Oct 12, 2021

LibreOffice has an improper certificate validation vulnerability that allows attackers to modify digitally signed ODF documents and insert bogus signing timestamps. LibreOffice incorrectly presents th...

CVE-2021-25633

HIGH CVSS 7.5 Oct 11, 2021

This vulnerability allows attackers to create digitally signed LibreOffice documents that appear valid but contain manipulated content unrelated to the displayed signature. By tampering with certifica...

CVE-2025-14714

MEDIUM CVSS 6.5 Dec 15, 2025

This CVE describes an authentication bypass vulnerability in LibreOffice on macOS where the bundled Python interpreter inherits the main application's TCC permissions. Attackers can execute scripts di...

CVE-2025-2866

MEDIUM CVSS 5.5 Apr 27, 2025

A cryptographic signature verification flaw in LibreOffice allows attackers to spoof PDF signatures by making invalid signatures appear valid. This affects users who rely on LibreOffice's PDF signatur...

CVE-2021-25635

MEDIUM CVSS 5.5 Mar 21, 2025

This vulnerability allows attackers to forge digital signatures in LibreOffice documents. An attacker can modify a signed ODF document to use an invalid signature algorithm, making LibreOffice incorre...

CVE-2024-3044

MEDIUM CVSS 6.5 May 14, 2024

This vulnerability in LibreOffice allows attackers to embed malicious scripts in documents that execute automatically when users click on graphics, bypassing previous security prompts. It affects Libr...