CVE-2026-8358Heap buffer overflow in spreadsheet tracked-changes import Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-8357Heap buffer overflow in Calc formula compilation Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-8356Stack buffer overflow in PPT presentation import Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-6047Heap buffer overflow in OOXML text box element import Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-6045Heap buffer overflow in EMF+ gradient brush import Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-6040Heap use-after-free in ODF number-format blank-width parsing Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-6039Heap buffer overflow in DXF polyline import Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/15/2026 Severity Medium CVE-2026-4430Heap Buffer Overflow in AgileEngine Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 05/07/2026 Severity Medium CVE-2025-14714TCC Bypass via Inherited Permissions in Bundled Interpreter Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 12/15/2025 Severity Low CVE-2025-2866PDF signature forgery with adbe.pkcs7.sha1 SubFilter Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 04/27/2025 Severity Low CVE-2021-25635Content Manipulation with Certificate Validation Attack Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 03/21/2025 Severity Medium CVE-2025-1080Macro URL arbitrary script execution Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 03/04/2025 Severity High CVE-2025-0514Executable hyperlink Windows path targets executed unconditionally on activation Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 02/25/2025 Severity High CVE-2024-12426URL fetching can be used to exfiltrate arbitrary INI file values and environment variables Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 01/07/2025 Severity Medium CVE-2024-12425Path traversal leading to arbitrary .ttf file write Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 01/07/2025 Severity Low CVE-2024-7788Signatures in "repair mode" should not be trusted Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 09/17/2024 Severity High CVE-2024-6472Ability to trust not validated macro signatures removed in high security mode Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 08/05/2024 Severity High CVE-2024-5261TLS certificate are not properly verified when utilizing LibreOfficeKit Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 06/25/2024 Severity Critical CVE-2024-3044Graphic on-click binding allows unchecked script execution Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 05/14/2024 Severity Medium CVE-2023-6186Link targets allow arbitrary script execution Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 12/11/2023 Severity High CVE-2023-6185Improper input validation enabling arbitrary Gstreamer pipeline injection Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 12/11/2023 Severity High CVE-2023-0950Array Index UnderFlow in Calc Formula Parsing Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 05/25/2023 Severity High CVE-2023-2255Remote documents loaded without prompt via IFrame Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 05/25/2023 Severity Unknown CVE-2022-3140Macro URL arbitrary script execution Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 10/11/2022 Severity Unknown CVE-2022-26307Weak Master Keys Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 07/25/2022 Severity Unknown CVE-2022-26305Execution of Untrusted Macros Due to Improper Certificate Validation Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 07/25/2022 Severity Unknown CVE-2022-26306Execution of Untrusted Macros Due to Improper Certificate Validation Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 07/25/2022 Severity Unknown CVE-2021-25636Incorrect trust validation of signature with ambiguous KeyInfo children Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 02/22/2022 Severity Unknown CVE-2021-25634Timestamp Manipulation with Signature Wrapping Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 10/12/2021 Severity Unknown CVE-2021-25633Content Manipulation with Double Certificate Attack Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 10/11/2021 Severity Unknown CVE-2021-25631denylist of executable filename extensions possible to bypass under windows Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 05/03/2021 Severity Unknown CVE-2021-25630Exploitation status Not confirmed Fix YesAffected product L LibreOffice Online Published 02/23/2021 Severity Unknown CVE-2020-12803XForms submissions could overwrite local files Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 06/08/2020 Severity Unknown CVE-2020-12802remote graphics contained in docx format retrieved in 'stealth mode' Exploitation status Not confirmed Fix YesAffected product L LibreOffice Published 06/08/2020 Severity Unknown CVE-2020-12801Crash-recovered MSOffice encrypted documents defaulted to not to using encryption on next save Exploitation status Not known exploited Fix YesAffected product L LibreOffice Published 05/18/2020 Severity Unknown