PHPOffice kayıtları
phpoffice üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-611 Improper Restriction of XML External Entity Reference5
- CWE-36 Absolute Path Traversal2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-502 Deserialization of Untrusted Data1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2018-19277Kavram kanıtı | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx filephpoffice · phpspreadsheet · CWE-91 | Yüksek8,8 | — | %7,8 | 14 Kas 2018 |
36İzleyin | CVE-2026-34084İstismar yok | PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadphpoffice · phpspreadsheet · CWE-502 | Kritik9,2 | — | %0,8 | 5 May 2026 |
35İzleyin | CVE-2019-12331İstismar yok | PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue.phpoffice · phpspreadsheet · CWE-611 | Yüksek8,8 | — | %1,4 | 7 Kas 2019 |
35İzleyin | CVE-2024-45291İstismar yok | Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-36 | Yüksek8,8 | — | %0,9 | 7 Eki 2024 |
33İzleyin | CVE-2024-56408İstismar yok | PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` filephpoffice · phpspreadsheet · CWE-79 | Yüksek8,3 | — | %0,4 | 3 Oca 2025 |
33İzleyin | CVE-2024-56409İstismar yok | PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php filephpoffice · phpspreadsheet · CWE-79 | Yüksek8,3 | — | %0,3 | 3 Oca 2025 |
33İzleyin | CVE-2024-56366İstismar yok | PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php filephpoffice · phpspreadsheet · CWE-79 | Yüksek8,3 | — | %0,3 | 3 Oca 2025 |
33İzleyin | CVE-2024-56365İstismar yok | PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader classphpoffice · phpspreadsheet · CWE-79 | Yüksek8,3 | — | %0,3 | 3 Oca 2025 |
31İzleyin | CVE-2024-45293Kavram kanıtı | XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX readerphpoffice · phpspreadsheet · CWE-611 | Yüksek7,5 | — | %2,8 | 7 Eki 2024 |
30İzleyin | CVE-2024-47873İstismar yok | PhpSpreadsheet XmlScanner bypass leads to XXEphpoffice · phpspreadsheet · CWE-611 | Yüksek7,5 | — | %0,7 | 18 Kas 2024 |
30İzleyin | CVE-2024-48917İstismar yok | XXE in PHPSpreadsheet's XLSX readerphpoffice · phpspreadsheet · CWE-611 | Yüksek7,5 | — | %0,7 | 18 Kas 2024 |
30İzleyin | CVE-2024-45290İstismar yok | Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-36 | Yüksek7,5 | — | %0,6 | 7 Eki 2024 |
30İzleyin | CVE-2026-40902İstismar yok | PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensionsphpoffice · phpspreadsheet · CWE-770 | Yüksek7,5 | — | %0,5 | 12 May 2026 |
30İzleyin | CVE-2026-40863İstismar yok | PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Readerphpoffice · phpspreadsheet · CWE-770 | Yüksek7,5 | — | %0,5 | 12 May 2026 |
26İzleyin | CVE-2024-45048İstismar yok | XML External Entity Reference (XXE) in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-611 | Orta6,5 | — | %0,6 | 28 Ağu 2024 |
25İzleyin | CVE-2020-7776İstismar yok | Cross-site Scripting (XSS)phpoffice · phpspreadsheet · CWE-79 | Orta6,4 | — | %1,3 | 9 Ara 2020 |
24İzleyin | CVE-2024-45060İstismar yok | Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-79 | Orta6,1 | — | %0,5 | 7 Eki 2024 |
21İzleyin | CVE-2024-45046İstismar yok | PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style informationphpoffice · phpspreadsheet · CWE-79 | Orta5,4 | — | %0,4 | 28 Ağu 2024 |
21İzleyin | CVE-2024-45292İstismar yok | PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinksphpoffice · phpspreadsheet · CWE-79 | Orta5,4 | — | %0,3 | 7 Eki 2024 |
21İzleyin | CVE-2026-40296İstismar yok | PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codesphpoffice · phpspreadsheet · CWE-79 | Orta5,4 | — | %0,2 | 6 May 2026 |
20İzleyin | CVE-2025-22131Kavram kanıtı | Cross-Site Scripting (XSS) vulnerability in generateNavigation() functionphpoffice · phpspreadsheet · CWE-79 | Orta5,1 | — | %0,4 | 20 Oca 2025 |
19İzleyin | CVE-2024-56412İstismar yok | PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special charactersphpoffice · phpspreadsheet · CWE-79 | Orta4,8 | — | %0,4 | 3 Oca 2025 |
19İzleyin | CVE-2024-56411İstismar yok | PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page headerphpoffice · phpspreadsheet · CWE-79 | Orta4,8 | — | %0,4 | 3 Oca 2025 |
19İzleyin | CVE-2024-56410İstismar yok | PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom propertiesphpoffice · phpspreadsheet · CWE-79 | Orta4,8 | — | %0,3 | 3 Oca 2025 |
19İzleyin | CVE-2026-35453İstismar yok | PhpSpreadsheet XSS via number format text substitution in HTML Writerphpoffice · phpspreadsheet · CWE-79 | Orta4,8 | — | %0,2 | 5 May 2026 |
- CVE-2018-1927737İzleyin
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
YüksekCVSS 8,8Kavram kanıtıEPSS %8phpoffice · phpspreadsheet14 Kas 2018
- CVE-2026-3408436İzleyin
PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load
KritikCVSS 9,2İstismar yokEPSS %1phpoffice · phpspreadsheet5 May 2026
- CVE-2019-1233135İzleyin
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue.
YüksekCVSS 8,8İstismar yokEPSS %1phpoffice · phpspreadsheet7 Kas 2019
- CVE-2024-4529135İzleyin
Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet
YüksekCVSS 8,8İstismar yokEPSS %1phpoffice · phpspreadsheet7 Eki 2024
- CVE-2024-5640833İzleyin
PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file
YüksekCVSS 8,3İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-5640933İzleyin
PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file
YüksekCVSS 8,3İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-5636633İzleyin
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file
YüksekCVSS 8,3İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-5636533İzleyin
PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class
YüksekCVSS 8,3İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-4529331İzleyin
XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpoffice · phpspreadsheet7 Eki 2024
- CVE-2024-4787330İzleyin
PhpSpreadsheet XmlScanner bypass leads to XXE
YüksekCVSS 7,5İstismar yokEPSS %1phpoffice · phpspreadsheet18 Kas 2024
- CVE-2024-4891730İzleyin
XXE in PHPSpreadsheet's XLSX reader
YüksekCVSS 7,5İstismar yokEPSS %1phpoffice · phpspreadsheet18 Kas 2024
- CVE-2024-4529030İzleyin
Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet
YüksekCVSS 7,5İstismar yokEPSS %1phpoffice · phpspreadsheet7 Eki 2024
- CVE-2026-4090230İzleyin
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
YüksekCVSS 7,5İstismar yokEPSS %0phpoffice · phpspreadsheet12 May 2026
- CVE-2026-4086330İzleyin
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
YüksekCVSS 7,5İstismar yokEPSS %0phpoffice · phpspreadsheet12 May 2026
- CVE-2024-4504826İzleyin
XML External Entity Reference (XXE) in PHPSpreadsheet
OrtaCVSS 6,5İstismar yokEPSS %1phpoffice · phpspreadsheet28 Ağu 2024
- CVE-2020-777625İzleyin
Cross-site Scripting (XSS)
OrtaCVSS 6,4İstismar yokEPSS %1phpoffice · phpspreadsheet9 Ara 2020
- CVE-2024-4506024İzleyin
Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet
OrtaCVSS 6,1İstismar yokEPSS %1phpoffice · phpspreadsheet7 Eki 2024
- CVE-2024-4504621İzleyin
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
OrtaCVSS 5,4İstismar yokEPSS %0phpoffice · phpspreadsheet28 Ağu 2024
- CVE-2024-4529221İzleyin
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
OrtaCVSS 5,4İstismar yokEPSS %0phpoffice · phpspreadsheet7 Eki 2024
- CVE-2026-4029621İzleyin
PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes
OrtaCVSS 5,4İstismar yokEPSS %0phpoffice · phpspreadsheet6 May 2026
- CVE-2025-2213120İzleyin
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function
OrtaCVSS 5,1Kavram kanıtıEPSS %0phpoffice · phpspreadsheet20 Oca 2025
- CVE-2024-5641219İzleyin
PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters
OrtaCVSS 4,8İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-5641119İzleyin
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
OrtaCVSS 4,8İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2024-5641019İzleyin
PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties
OrtaCVSS 4,8İstismar yokEPSS %0phpoffice · phpspreadsheet3 Oca 2025
- CVE-2026-3545319İzleyin
PhpSpreadsheet XSS via number format text substitution in HTML Writer
OrtaCVSS 4,8İstismar yokEPSS %0phpoffice · phpspreadsheet5 May 2026