Where
-Infinity
0

composer/phpoffice/phpspreadsheetCross-Site Scripting (XSS) vulnerability in generateNavigation() function

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters

Risk 34
Severity
5.4
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header

Risk 34
Severity
5.4
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties

Risk 34
Severity
5.4
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file

Risk 67
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/phpoffice/phpspreadsheetPhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

Risk 67
Severity
8.3
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

Risk 67
Severity
8.3
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file

Risk 67
Severity
8.3
First published (updated )

composer/phpoffice/phpspreadsheetXXE in PHPSpreadsheet's XLSX reader

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet XmlScanner bypass leads to XXE

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/phpoffice/phpspreadsheetXML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader

Risk 45
Severity
7.5
First published (updated )

composer/phpoffice/phpspreadsheetPhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks

Risk 35
Severity
5.4
First published (updated )

PHPOffice phpspreadsheetPath traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet

Risk 82
Severity
8.8
First published (updated )

PHPOffice phpspreadsheetPath traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet

Risk 45
Severity
7.7
First published (updated )

PHPOffice phpspreadsheetUnauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet

Risk 49
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PHPOffice phpspreadsheetPhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information

Risk 35
Severity
5.4
First published (updated )

composer/phpoffice/phpspreadsheetXML External Entity Reference (XXE) in PHPSpreadsheet

Risk 80
Severity
8.8
First published (updated )

composer/phpoffice/phpspreadsheetXEE

Risk 80
Severity
8.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203