VendorsPHPOfficephpspreadsheetany version
Vulnerabilities

PHPOffice Phpspreadsheet any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2026-34084
PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load
Published 2026-05-05 · Analyzed
9.8EPSS 0.008
CVE-2018-19277
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
Published 2018-11-14 · Modified
8.81 PoCEPSS 0.078
CVE-2019-12331
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the fix is not sufficient. By double-encoding the the xml payload to utf-7 it is possible to bypass the check for the string ‚<!ENTITY‘ and thus allowing for an xml external entity processing (XXE) attack.
Published 2019-11-07 · Modified
8.8EPSS 0.014
CVE-2024-45291
Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet
Published 2024-10-07 · Analyzed
8.8EPSS 0.009
CVE-2024-45048
XML External Entity Reference (XXE) in PHPSpreadsheet
Published 2024-08-28 · Analyzed
8.8EPSS 0.006
CVE-2024-56408
PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file
Published 2025-01-03 · Modified
8.3EPSS 0.004
CVE-2024-56409
PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file
Published 2025-01-03 · Analyzed
8.3EPSS 0.003
CVE-2024-56366
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file
Published 2025-01-03 · Analyzed
8.3EPSS 0.003
CVE-2024-56365
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class
Published 2025-01-03 · Analyzed
8.3EPSS 0.003
CVE-2024-45290
Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet
Published 2024-10-07 · Analyzed
7.7EPSS 0.006
CVE-2024-45293
XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader
Published 2024-10-07 · Analyzed
7.5EPSS 0.028
CVE-2024-47873
PhpSpreadsheet XmlScanner bypass leads to XXE
Published 2024-11-18 · Analyzed
7.5EPSS 0.007
CVE-2024-48917
XXE in PHPSpreadsheet's XLSX reader
Published 2024-11-18 · Analyzed
7.5EPSS 0.007
CVE-2026-40863
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
CVE-2026-40902
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
CVE-2020-7776
Cross-site Scripting (XSS)
Published 2020-12-09 · Modified
7.1EPSS 0.013
CVE-2024-45060
Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet
Published 2024-10-07 · Analyzed
7.1EPSS 0.005
CVE-2025-22131
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function
Published 2025-01-20 · Analyzed
6.1EPSS 0.004
CVE-2024-45046
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
Published 2024-08-28 · Analyzed
5.4EPSS 0.004
CVE-2024-56412
PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters
Published 2025-01-03 · Analyzed
5.4EPSS 0.004
CVE-2024-56411
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Published 2025-01-03 · Analyzed
5.4EPSS 0.004
CVE-2024-45292
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
Published 2024-10-07 · Analyzed
5.4EPSS 0.003
CVE-2024-56410
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties
Published 2025-01-03 · Analyzed
5.4EPSS 0.003
CVE-2026-40296
PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes
Published 2026-05-06 · Analyzed
5.4EPSS 0.002
CVE-2026-35453
PhpSpreadsheet XSS via number format text substitution in HTML Writer
Published 2026-05-05 · Analyzed
5.4EPSS 0.002