All 28 CVE vulnerabilities found in PhpSpreadsheet, with AI-generated Chinese analysis, references, and POCs.
This page documents security vulnerabilities for PhpSpreadsheet, an open-source PHP library for reading and writing spreadsheet files, categorized under weak cryptographic implementations and input validation flaws. It aggregates a comprehensive list of known issues affecting this specific product, covering historical data from its early releases through recent updates up to the present day. By consulting this resource, users can systematically track vendor advisories issued by the PhpSpreadsheet development team to stay informed about emerging threats. Readers are able to understand the technical context and severity of common weakness classes associated with library manipulation, such as formula injection or file path traversal. Furthermore, the page provides a clear lookup of the product’s vulnerability history, allowing developers and security analysts to review past incidents and assess the overall security posture of the software over time. This centralized view aids in risk management by highlighting patterns in flaw types and release cycles, facilitating more informed decisions regarding dependency updates and patch implementation. The data is compiled from official security channels and public databases to ensure accuracy and completeness for the PhpSpreadsheet ecosystem.
Vendor: PHPOffice
All 28 known CVE vulnerabilities affecting PhpSpreadsheet with full Chinese analysis, references, and POCs where available.