PHPOffice records
25 published records for vendor phpoffice.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-611 Improper Restriction of XML External Entity Reference5
- CWE-36 Absolute Path Traversal2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-502 Deserialization of Untrusted Data1
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2018-19277Proof of concept | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx filephpoffice · phpspreadsheet · CWE-91 | High8.8 | — | 7.8% | Nov 14, 2018 |
36Monitor | CVE-2026-34084No exploit | PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadphpoffice · phpspreadsheet · CWE-502 | Critical9.2 | — | 0.8% | May 5, 2026 |
35Monitor | CVE-2019-12331No exploit | PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue.phpoffice · phpspreadsheet · CWE-611 | High8.8 | — | 1.4% | Nov 7, 2019 |
35Monitor | CVE-2024-45291No exploit | Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-36 | High8.8 | — | 0.9% | Oct 7, 2024 |
33Monitor | CVE-2024-56408No exploit | PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` filephpoffice · phpspreadsheet · CWE-79 | High8.3 | — | 0.4% | Jan 3, 2025 |
33Monitor | CVE-2024-56409No exploit | PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php filephpoffice · phpspreadsheet · CWE-79 | High8.3 | — | 0.3% | Jan 3, 2025 |
33Monitor | CVE-2024-56366No exploit | PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php filephpoffice · phpspreadsheet · CWE-79 | High8.3 | — | 0.3% | Jan 3, 2025 |
33Monitor | CVE-2024-56365No exploit | PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader classphpoffice · phpspreadsheet · CWE-79 | High8.3 | — | 0.3% | Jan 3, 2025 |
31Monitor | CVE-2024-45293Proof of concept | XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX readerphpoffice · phpspreadsheet · CWE-611 | High7.5 | — | 2.8% | Oct 7, 2024 |
30Monitor | CVE-2024-47873No exploit | PhpSpreadsheet XmlScanner bypass leads to XXEphpoffice · phpspreadsheet · CWE-611 | High7.5 | — | 0.7% | Nov 18, 2024 |
30Monitor | CVE-2024-48917No exploit | XXE in PHPSpreadsheet's XLSX readerphpoffice · phpspreadsheet · CWE-611 | High7.5 | — | 0.7% | Nov 18, 2024 |
30Monitor | CVE-2024-45290No exploit | Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-36 | High7.5 | — | 0.6% | Oct 7, 2024 |
30Monitor | CVE-2026-40902No exploit | PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensionsphpoffice · phpspreadsheet · CWE-770 | High7.5 | — | 0.5% | May 12, 2026 |
30Monitor | CVE-2026-40863No exploit | PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Readerphpoffice · phpspreadsheet · CWE-770 | High7.5 | — | 0.5% | May 12, 2026 |
26Monitor | CVE-2024-45048No exploit | XML External Entity Reference (XXE) in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-611 | Medium6.5 | — | 0.6% | Aug 28, 2024 |
25Monitor | CVE-2020-7776No exploit | Cross-site Scripting (XSS)phpoffice · phpspreadsheet · CWE-79 | Medium6.4 | — | 1.3% | Dec 9, 2020 |
24Monitor | CVE-2024-45060No exploit | Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-79 | Medium6.1 | — | 0.5% | Oct 7, 2024 |
21Monitor | CVE-2024-45046No exploit | PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style informationphpoffice · phpspreadsheet · CWE-79 | Medium5.4 | — | 0.4% | Aug 28, 2024 |
21Monitor | CVE-2024-45292No exploit | PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinksphpoffice · phpspreadsheet · CWE-79 | Medium5.4 | — | 0.3% | Oct 7, 2024 |
21Monitor | CVE-2026-40296No exploit | PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codesphpoffice · phpspreadsheet · CWE-79 | Medium5.4 | — | 0.2% | May 6, 2026 |
20Monitor | CVE-2025-22131Proof of concept | Cross-Site Scripting (XSS) vulnerability in generateNavigation() functionphpoffice · phpspreadsheet · CWE-79 | Medium5.1 | — | 0.4% | Jan 20, 2025 |
19Monitor | CVE-2024-56412No exploit | PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special charactersphpoffice · phpspreadsheet · CWE-79 | Medium4.8 | — | 0.4% | Jan 3, 2025 |
19Monitor | CVE-2024-56411No exploit | PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page headerphpoffice · phpspreadsheet · CWE-79 | Medium4.8 | — | 0.4% | Jan 3, 2025 |
19Monitor | CVE-2024-56410No exploit | PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom propertiesphpoffice · phpspreadsheet · CWE-79 | Medium4.8 | — | 0.3% | Jan 3, 2025 |
19Monitor | CVE-2026-35453No exploit | PhpSpreadsheet XSS via number format text substitution in HTML Writerphpoffice · phpspreadsheet · CWE-79 | Medium4.8 | — | 0.2% | May 5, 2026 |
- CVE-2018-1927737Monitor
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
HighCVSS 8.8Proof of conceptEPSS 8%phpoffice · phpspreadsheetNov 14, 2018
- CVE-2026-3408436Monitor
PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load
CriticalCVSS 9.2No exploitEPSS 1%phpoffice · phpspreadsheetMay 5, 2026
- CVE-2019-1233135Monitor
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue.
HighCVSS 8.8No exploitEPSS 1%phpoffice · phpspreadsheetNov 7, 2019
- CVE-2024-4529135Monitor
Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet
HighCVSS 8.8No exploitEPSS 1%phpoffice · phpspreadsheetOct 7, 2024
- CVE-2024-5640833Monitor
PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file
HighCVSS 8.3No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-5640933Monitor
PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file
HighCVSS 8.3No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-5636633Monitor
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file
HighCVSS 8.3No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-5636533Monitor
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class
HighCVSS 8.3No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-4529331Monitor
XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader
HighCVSS 7.5Proof of conceptEPSS 3%phpoffice · phpspreadsheetOct 7, 2024
- CVE-2024-4787330Monitor
PhpSpreadsheet XmlScanner bypass leads to XXE
HighCVSS 7.5No exploitEPSS 1%phpoffice · phpspreadsheetNov 18, 2024
- CVE-2024-4891730Monitor
XXE in PHPSpreadsheet's XLSX reader
HighCVSS 7.5No exploitEPSS 1%phpoffice · phpspreadsheetNov 18, 2024
- CVE-2024-4529030Monitor
Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet
HighCVSS 7.5No exploitEPSS 1%phpoffice · phpspreadsheetOct 7, 2024
- CVE-2026-4090230Monitor
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
HighCVSS 7.5No exploitEPSS 0%phpoffice · phpspreadsheetMay 12, 2026
- CVE-2026-4086330Monitor
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
HighCVSS 7.5No exploitEPSS 0%phpoffice · phpspreadsheetMay 12, 2026
- CVE-2024-4504826Monitor
XML External Entity Reference (XXE) in PHPSpreadsheet
MediumCVSS 6.5No exploitEPSS 1%phpoffice · phpspreadsheetAug 28, 2024
- CVE-2020-777625Monitor
Cross-site Scripting (XSS)
MediumCVSS 6.4No exploitEPSS 1%phpoffice · phpspreadsheetDec 9, 2020
- CVE-2024-4506024Monitor
Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet
MediumCVSS 6.1No exploitEPSS 1%phpoffice · phpspreadsheetOct 7, 2024
- CVE-2024-4504621Monitor
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
MediumCVSS 5.4No exploitEPSS 0%phpoffice · phpspreadsheetAug 28, 2024
- CVE-2024-4529221Monitor
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
MediumCVSS 5.4No exploitEPSS 0%phpoffice · phpspreadsheetOct 7, 2024
- CVE-2026-4029621Monitor
PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes
MediumCVSS 5.4No exploitEPSS 0%phpoffice · phpspreadsheetMay 6, 2026
- CVE-2025-2213120Monitor
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function
MediumCVSS 5.1Proof of conceptEPSS 0%phpoffice · phpspreadsheetJan 20, 2025
- CVE-2024-5641219Monitor
PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters
MediumCVSS 4.8No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-5641119Monitor
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
MediumCVSS 4.8No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2024-5641019Monitor
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties
MediumCVSS 4.8No exploitEPSS 0%phpoffice · phpspreadsheetJan 3, 2025
- CVE-2026-3545319Monitor
PhpSpreadsheet XSS via number format text substitution in HTML Writer
MediumCVSS 4.8No exploitEPSS 0%phpoffice · phpspreadsheetMay 5, 2026