CVE-2025-23210
- EPSS 0.41%
- Veröffentlicht 03.02.2025 22:15:28
- Zuletzt bearbeitet 15.04.2026 00:35:42
phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue ...
CVE-2025-22131
- EPSS 0.38%
- Veröffentlicht 20.01.2025 16:15:27
- Zuletzt bearbeitet 06.03.2025 13:30:34
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.
CVE-2024-56412
- EPSS 0.38%
- Veröffentlicht 03.01.2025 18:15:16
- Zuletzt bearbeitet 06.03.2025 13:30:34
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attac...
CVE-2024-56411
- EPSS 0.36%
- Veröffentlicht 03.01.2025 18:15:16
- Zuletzt bearbeitet 06.03.2025 13:30:34
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed withou...
CVE-2024-56410
- EPSS 0.33%
- Veröffentlicht 03.01.2025 18:15:15
- Zuletzt bearbeitet 17.04.2025 02:35:48
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom prop...
CVE-2024-56409
- EPSS 0.33%
- Veröffentlicht 03.01.2025 17:15:08
- Zuletzt bearbeitet 21.04.2025 17:14:40
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspr...
CVE-2024-56366
- EPSS 0.33%
- Veröffentlicht 03.01.2025 17:15:08
- Zuletzt bearbeitet 21.04.2025 16:57:02
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phps...
CVE-2024-56365
- EPSS 0.32%
- Veröffentlicht 03.01.2025 17:15:08
- Zuletzt bearbeitet 21.04.2025 16:57:39
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendo...
CVE-2024-56408
- EPSS 0.4%
- Veröffentlicht 03.01.2025 16:15:26
- Zuletzt bearbeitet 20.05.2025 19:15:49
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` file, which leads to th...
CVE-2024-48917
- EPSS 0.72%
- Veröffentlicht 18.11.2024 20:15:05
- Zuletzt bearbeitet 07.03.2025 16:48:11
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks. However, in a bypass of the previously reported `CVE-2024-47873`, the regexes from the `findCharSet`...