Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PhpSpreadsheet — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in PhpSpreadsheet, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for PhpSpreadsheet, an open-source PHP library for reading and writing office documents, focusing primarily on security weaknesses in its parsing and serialization logic. The collection covers documented security flaws, including deserialization issues, XML injection, and arbitrary code execution risks, spanning releases from earlier minor versions through the latest stable build. Here you can track the vendor’s published security advisories, analyze the recurring weakness classes affecting spreadsheet parsing, and review the product’s full vulnerability history. The entries are organized by severity and affected versions, enabling users to identify which specific releases require immediate patching. Each record includes the affected component, a concise description of the flaw, and references to the official advisory, providing a clear audit trail for compliance and risk assessment.

Vendor: PHPOffice

CVE ID Title CVSS Severity Published
CVE-2026-59932 PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion CWE-400 7.5 High 2026-07-28
CVE-2026-59933 PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion CWE-400 7.5 High 2026-07-28
CVE-2026-59931 PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist CWE-918 7.7 High 2026-07-28
CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass CWE-502 - - 2026-06-22
CVE-2026-40863 PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader CWE-770 7.5 High 2026-05-12
CVE-2026-40902 PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions CWE-770 7.5 High 2026-05-12
CVE-2026-40296 PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes CWE-79 5.4 Medium 2026-05-06
CVE-2026-35453 PhpSpreadsheet XSS via number format text substitution in HTML Writer CWE-79 5.3 - 2026-05-05
CVE-2026-34084 PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load CWE-502 9.1 - 2026-05-05
CVE-2025-54370 PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser CWE-918 9.8AI Critical AI 2025-08-25
CVE-2025-23210 Bypass XSS sanitizer using the javascript protocol and special characters in phpoffice/phpspreadsheet CWE-79 6.1 - 2025-02-03
CVE-2025-22131 Cross-Site Scripting (XSS) vulnerability in generateNavigation() function CWE-79 6.1 - 2025-01-20
CVE-2024-56412 PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters CWE-79 6.1 - 2025-01-03
CVE-2024-56411 PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header CWE-79 6.1 - 2025-01-03
CVE-2024-56410 PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties CWE-79 6.1 - 2025-01-03
CVE-2024-56409 PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file CWE-79 6.1 - 2025-01-03
CVE-2024-56366 PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file CWE-79 6.1 - 2025-01-03
CVE-2024-56365 PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class CWE-79 6.1 - 2025-01-03
CVE-2024-56408 PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file CWE-79 6.1 - 2025-01-03
CVE-2024-48917 XXE in PHPSpreadsheet's XLSX reader CWE-611 7.5 High 2024-11-18
CVE-2024-47873 PhpSpreadsheet XmlScanner bypass leads to XXE CWE-611 7.5 High 2024-11-18
CVE-2024-45060 Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet CWE-79 7.1 High 2024-10-07
CVE-2024-45290 Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet CWE-36 7.7 High 2024-10-07
CVE-2024-45291 Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet CWE-36 6.3 Medium 2024-10-07
CVE-2024-45292 PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks CWE-79 5.4 Medium 2024-10-07
CVE-2024-45293 XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader CWE-611 7.5 High 2024-10-07
CVE-2024-45046 PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information CWE-79 5.4 Medium 2024-08-28
CVE-2024-45048 XML External Entity Reference (XXE) in PHPSpreadsheet CWE-611 8.8 High 2024-08-28

All 28 known CVE vulnerabilities affecting PhpSpreadsheet with full Chinese analysis, references, and POCs where available.