Skip to content
Noroxi

PHPOffice records

25 published records for vendor phpoffice.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

25 records
  • securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    HighCVSS 8.8Proof of conceptEPSS 8%

    phpoffice · phpspreadsheetNov 14, 2018

  • PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load

    CriticalCVSS 9.2No exploitEPSS 1%

    phpoffice · phpspreadsheetMay 5, 2026

  • PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue.

    HighCVSS 8.8No exploitEPSS 1%

    phpoffice · phpspreadsheetNov 7, 2019

  • Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet

    HighCVSS 8.8No exploitEPSS 1%

    phpoffice · phpspreadsheetOct 7, 2024

  • PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file

    HighCVSS 8.3No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file

    HighCVSS 8.3No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

    HighCVSS 8.3No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

    HighCVSS 8.3No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpoffice · phpspreadsheetOct 7, 2024

  • PhpSpreadsheet XmlScanner bypass leads to XXE

    HighCVSS 7.5No exploitEPSS 1%

    phpoffice · phpspreadsheetNov 18, 2024

  • XXE in PHPSpreadsheet's XLSX reader

    HighCVSS 7.5No exploitEPSS 1%

    phpoffice · phpspreadsheetNov 18, 2024

  • Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet

    HighCVSS 7.5No exploitEPSS 1%

    phpoffice · phpspreadsheetOct 7, 2024

  • PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

    HighCVSS 7.5No exploitEPSS 0%

    phpoffice · phpspreadsheetMay 12, 2026

  • PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

    HighCVSS 7.5No exploitEPSS 0%

    phpoffice · phpspreadsheetMay 12, 2026

  • XML External Entity Reference (XXE) in PHPSpreadsheet

    MediumCVSS 6.5No exploitEPSS 1%

    phpoffice · phpspreadsheetAug 28, 2024

  • CVE-2020-7776
    25Monitor

    Cross-site Scripting (XSS)

    MediumCVSS 6.4No exploitEPSS 1%

    phpoffice · phpspreadsheetDec 9, 2020

  • Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet

    MediumCVSS 6.1No exploitEPSS 1%

    phpoffice · phpspreadsheetOct 7, 2024

  • PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information

    MediumCVSS 5.4No exploitEPSS 0%

    phpoffice · phpspreadsheetAug 28, 2024

  • PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks

    MediumCVSS 5.4No exploitEPSS 0%

    phpoffice · phpspreadsheetOct 7, 2024

  • PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes

    MediumCVSS 5.4No exploitEPSS 0%

    phpoffice · phpspreadsheetMay 6, 2026

  • Cross-Site Scripting (XSS) vulnerability in generateNavigation() function

    MediumCVSS 5.1Proof of conceptEPSS 0%

    phpoffice · phpspreadsheetJan 20, 2025

  • PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters

    MediumCVSS 4.8No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header

    MediumCVSS 4.8No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties

    MediumCVSS 4.8No exploitEPSS 0%

    phpoffice · phpspreadsheetJan 3, 2025

  • PhpSpreadsheet XSS via number format text substitution in HTML Writer

    MediumCVSS 4.8No exploitEPSS 0%

    phpoffice · phpspreadsheetMay 5, 2026