Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PhpSpreadsheet — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in PhpSpreadsheet, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities for PhpSpreadsheet, an open-source PHP library for reading and writing spreadsheet files, categorized under weak cryptographic implementations and input validation flaws. It aggregates a comprehensive list of known issues affecting this specific product, covering historical data from its early releases through recent updates up to the present day. By consulting this resource, users can systematically track vendor advisories issued by the PhpSpreadsheet development team to stay informed about emerging threats. Readers are able to understand the technical context and severity of common weakness classes associated with library manipulation, such as formula injection or file path traversal. Furthermore, the page provides a clear lookup of the product’s vulnerability history, allowing developers and security analysts to review past incidents and assess the overall security posture of the software over time. This centralized view aids in risk management by highlighting patterns in flaw types and release cycles, facilitating more informed decisions regarding dependency updates and patch implementation. The data is compiled from official security channels and public databases to ensure accuracy and completeness for the PhpSpreadsheet ecosystem.

Vendor: PHPOffice

CVE IDTitleCVSSSeverityPublished
CVE-2026-59932 PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion CWE-400 7.5 High2026-07-28
CVE-2026-59933 PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion CWE-400 7.5 High2026-07-28
CVE-2026-59931 PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist CWE-918 7.7 High2026-07-28
CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass CWE-502--2026-06-22
CVE-2026-40863 PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader CWE-770 7.5 High2026-05-12
CVE-2026-40902 PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions CWE-770 7.5 High2026-05-12
CVE-2026-40296 PhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes CWE-79 5.4 Medium2026-05-06
CVE-2026-35453 PhpSpreadsheet XSS via number format text substitution in HTML Writer CWE-79 5.3 -2026-05-05
CVE-2026-34084 PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load CWE-502 9.1 -2026-05-05
CVE-2025-54370 PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser CWE-918 9.8AICriticalAI2025-08-25
CVE-2025-23210 Bypass XSS sanitizer using the javascript protocol and special characters in phpoffice/phpspreadsheet CWE-79 6.1 -2025-02-03
CVE-2025-22131 Cross-Site Scripting (XSS) vulnerability in generateNavigation() function CWE-79 6.1 -2025-01-20
CVE-2024-56412 PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters CWE-79 6.1 -2025-01-03
CVE-2024-56411 PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header CWE-79 6.1 -2025-01-03
CVE-2024-56410 PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties CWE-79 6.1 -2025-01-03
CVE-2024-56409 PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file CWE-79 6.1 -2025-01-03
CVE-2024-56366 PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file CWE-79 6.1 -2025-01-03
CVE-2024-56365 PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class CWE-79 6.1 -2025-01-03
CVE-2024-56408 PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file CWE-79 6.1 -2025-01-03
CVE-2024-48917 XXE in PHPSpreadsheet's XLSX reader CWE-611 7.5 High2024-11-18
CVE-2024-47873 PhpSpreadsheet XmlScanner bypass leads to XXE CWE-611 7.5 High2024-11-18
CVE-2024-45060 Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet CWE-79 7.1 High2024-10-07
CVE-2024-45290 Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet CWE-36 7.7 High2024-10-07
CVE-2024-45291 Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet CWE-36 6.3 Medium2024-10-07
CVE-2024-45292 PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks CWE-79 5.4 Medium2024-10-07
CVE-2024-45293 XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader CWE-611 7.5 High2024-10-07
CVE-2024-45046 PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information CWE-79 5.4 Medium2024-08-28
CVE-2024-45048 XML External Entity Reference (XXE) in PHPSpreadsheet CWE-611 8.8 High2024-08-28

All 28 known CVE vulnerabilities affecting PhpSpreadsheet with full Chinese analysis, references, and POCs where available.