CVE-2026-45034
- EPSS 0.35%
- Veröffentlicht 22.06.2026 20:32:32
- Zuletzt bearbeitet 23.06.2026 16:16:59
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme)...
CVE-2026-40863
- EPSS 0.4%
- Veröffentlicht 12.05.2026 22:04:29
- Zuletzt bearbeitet 13.05.2026 18:01:19
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row ...
CVE-2026-40902
- EPSS 0.4%
- Veröffentlicht 12.05.2026 22:02:39
- Zuletzt bearbeitet 14.05.2026 14:50:17
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method reads row numbers from XML attributes without vali...
CVE-2026-40296
- EPSS 0.23%
- Veröffentlicht 06.05.2026 20:48:34
- Zuletzt bearbeitet 11.05.2026 14:42:03
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs from the original value. When a cell has a custom number format containing the text ...
CVE-2026-35453
- EPSS 0.2%
- Veröffentlicht 05.05.2026 20:16:38
- Zuletzt bearbeitet 08.05.2026 17:08:50
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 through 5.6.0, the HTML Writer skips htmlspecialchars() output escaping ...
CVE-2026-34084
- EPSS 0.71%
- Veröffentlicht 05.05.2026 20:16:37
- Zuletzt bearbeitet 08.05.2026 17:10:03
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-c...
CVE-2025-54370
- EPSS 0.74%
- Veröffentlicht 25.08.2025 14:15:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1.12, 2.4.0, 3.10.0, and 5.0.0, SSRF can occur when a processed HTML document is read and displayed in the browser. The vulnerabilit...
CVE-2025-23210
- EPSS 0.39%
- Veröffentlicht 03.02.2025 22:15:28
- Zuletzt bearbeitet 15.04.2026 00:35:42
phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue ...
CVE-2025-22131
- EPSS 0.37%
- Veröffentlicht 20.01.2025 16:15:27
- Zuletzt bearbeitet 06.03.2025 13:30:34
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.
CVE-2024-56412
- EPSS 0.37%
- Veröffentlicht 03.01.2025 18:15:16
- Zuletzt bearbeitet 06.03.2025 13:30:34
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attac...