Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an administrator opened the admin console and navigated to the history page, the document name was injected as unescaped HTML and executed as a script inside the context of the admin console. The administrator JSON web token (JWT) used for the websocket connection could be leaked through this flaw. Users should upgrade to Collabora Online 22.05.13 or higher; Collabora Online 21.11.9.1 or higher; Collabora Online 6.4.27 or higher to receive a patch.
Conclusion & alert: CVE-2023-34088 is rated Moderate Risk (46/100): CVSS High severity, with low exploitation likelihood (EPSS 0.40%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.28% | 0.40% | +0.12% |
| 2 | 2026-06-01 | 0.10% | 0.28% | +0.19% |
| 3 | 2025-11-21 | — | 0.10% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 3.1 | HIGH |
|
2.3 | 5.8 | [email protected] |
| 5.4 | 3.1 | MEDIUM |
|
2.3 | 2.7 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| collaboraoffice | collabora_online | < 6.4.27 | cpe:2.3:a:collaboraoffice:collabora_online:*:*:*:*:*:*:*:* |
| collaboraoffice | collabora_online | >= 21.0, < 21.11.9.1 | cpe:2.3:a:collaboraoffice:collabora_online:*:*:*:*:*:*:*:* |
| collaboraoffice | collabora_online | >= 22.0, < 22.05.13 | cpe:2.3:a:collaboraoffice:collabora_online:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/CollaboraOnline/online/security/advisories/GHSA-7582-pwfh-3pwr | Third Party Advisory |