PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
Modified: 7/23/2026
package
pkg:packagist/phpoffice/phpspreadsheet
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
Modified: 7/23/2026
Cross-site scripting in phpoffice/phpspreadsheet
Modified: 7/8/2026
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
Modified: 2/4/2026
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
Modified: 7/23/2026
XXE in PHPSpreadsheet's XLSX reader
Modified: 3/6/2025
PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
Modified: 5/8/2026
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Modified: 3/6/2025
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
Modified: 5/13/2026
XXE in PHPSpreadsheet's XLSX reader
Modified: 3/6/2025
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
Modified: 5/13/2026
PHPSpreadsheet has a patch bypass for CVE-2026-34084
Modified: 9/10/2026
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
Modified: 3/6/2025
XXE in PHPSpreadsheet encoding is returned
Modified: 3/6/2025
PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
Modified: 5/8/2026
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Modified: 3/6/2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
Modified: 9/10/2026
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
Modified: 3/6/2025
XmlScanner bypass leads to XXE
Modified: 3/6/2025
PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
Modified: 5/8/2026
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
Modified: 3/6/2025
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Modified: 3/6/2025
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
Modified: 3/6/2025
PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
Modified: 8/29/2025
PhpSpreadsheet has an Unauthenticated Cross-Site-Scripting (XSS) in sample file
Modified: 3/6/2025
XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue
Modified: 3/6/2025
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
Modified: 2/4/2026
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
Modified: 3/6/2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
Modified: 3/6/2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
Modified: 9/10/2026
XXE in PHPSpreadsheet due to encoding issue
Modified: 3/6/2025
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
Modified: 7/23/2026