PHPOffice maintains a focused library ecosystem centered on document-processing components such as PHPSpreadsheet, which despite its narrow product portfolio has achieved wide adoption in server-side web applications that generate, parse, and serve office documents. The vendor's vulnerability surface reflects the inherent complexity of office-format parsing and dynamic document generation, with recurring exposure in cross-site scripting, XML external entity injection, server-side request forgery, path traversal, and resource-exhaustion weaknesses that arise across document-handling pipelines. A moderate share of the vendor's disclosures acquire public exploit code, consistent with the appeal of document-parsing flaws for web-application attack chains. Defenders should monitor this vendor's releases closely for applications that accept user-supplied documents or dynamically generate spreadsheets and reports, as remediation often requires library updates across a distributed application landscape. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpoffice over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19277HIGH securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | Nov 14, 2018 | 8.8 | 42 | NO | YES |
CVE-2026-34084CRITICAL PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 th | May 5, 2026 | 9.8 | 38 | NO | NO |
CVE-2024-45293HIGH PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by sl | Oct 7, 2024 | 7.5 | 31 | NO | YES |
CVE-2018-14065CRITICAL XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. | Jul 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-40902HIGH PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRow | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-40863HIGH PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does no | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-40296MEDIUM PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs from the origi | May 6, 2026 | 5.4 | 26 | NO | NO |
CVE-2019-12331HIGH PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This wa | Nov 7, 2019 | 8.8 | 26 | NO | NO |
CVE-2024-45291HIGH PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When | Oct 7, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-35453MEDIUM PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 th | May 5, 2026 | 5.4 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpoffice.
Media articles that mention a CVE ID that affects a product developed by Phpoffice — matched by CVE ID, not by vendor name.