Vulnerabilities in PHPOffice
29 resultsVexday analysis
PHPOffice acumula 26 vulnerabilidades na base, com 6 divulgadas nos últimos 90 dias, indicando atividade contínua de descoberta de falhas. Nenhuma está sob exploração ativa conhecida (KEV), e apenas 2 são críticas, reduzindo a pressão imediata, mas a fraqueza dominante em Cross-Site Scripting (CWE-79) permanece um vetor de risco relevante para aplicações web que processam dados não confiáveis. O ritmo recente de divulgações sugere necessidade de monitoramento regular de patches.
CVE-2024-56411MEDIUMPhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page headerEPSS 0.4%CVE-2026-45034CRITICALPhpSpreadsheet: File::prohibitWrappers bypassEPSS 0.4%CVE-2024-56366HIGHPhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php fileEPSS 0.3%CVE-2024-56409HIGHPhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php fileEPSS 0.3%CVE-2024-56410MEDIUMPhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom propertiesEPSS 0.3%CVE-2024-45292MEDIUMPhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinksEPSS 0.3%CVE-2024-56365HIGHPhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader classEPSS 0.3%CVE-2026-40296MEDIUMPhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codesEPSS 0.2%CVE-2026-35453MEDIUMPhpSpreadsheet XSS via number format text substitution in HTML WriterEPSS 0.2%