Skip to main content

Vendor/product archive

kingsoft / wps_office CVEs

Beta · best-effort

10 CVEs tagged to kingsoft / wps_office2 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-57096

Published May 14, 2025

An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7263

Published Aug 15, 2024

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an ar…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-7262

Published Aug 15, 2024

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an ar…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-31275

Published Nov 27, 2023

An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32548

Published Jun 13, 2023

OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious se…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26081

Published Mar 17, 2022

The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25969

Published Mar 17, 2022

The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user inv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25943

Published Mar 9, 2022

The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25291

Published Sep 13, 2020

GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush:…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1