ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.
Conclusion & alert: CVE-2020-12803 is rated Moderate Risk (53.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.72%). Core evidence: EPSS rose +1.26% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.46% | 1.72% | +1.26% |
| 2 | 2026-03-16 | 0.55% | 0.46% | -0.09% |
| 3 | 2026-03-02 | — | 0.55% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2020-12803: 1 source package rows (libreoffice); 15 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 8. | https://security.alpinelinux.org/vuln/CVE-2020-12803 |
debian
|
low | CVE-2020-12803 low priority: Debian including 1 source packages (libreoffice), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-12803 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2020-12803 |
suse
|
medium | CVE-2020-12803 severity moderate: SUSE including 848 source package names (libreoffice-6.4.5.2-13.3.1, libreoffice-6.4.5.2-43.68.1, …), 938 product×package rows across 11 product lines (SUSE Linux Enterprise Software Development Kit 12 SP5, SUSE Linux Enterprise Workstation Extension 12 SP5, … (11 product lines)): Fixed 938. | https://www.suse.com/security/cve/CVE-2020-12803/ |
ubuntu
|
low | CVE-2020-12803 low priority: Ubuntu including 1 source packages (libreoffice), 12 status rows across 12 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, trusty, upstream, xenial): released 9, ignored 2, DNE 1. | https://ubuntu.com/security/CVE-2020-12803 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libreoffice | libreoffice | < 6.4.4 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |