PHPOffice Project develops document-processing libraries that parse and manipulate Microsoft Office file formats, with the durable signal centered on XML external entity (XXE) injection vulnerabilities that arise from permissive document parsing. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpoffice Project over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19277HIGH securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | Nov 14, 2018 | 8.8 | 42 | NO | YES |
CVE-2026-34084CRITICAL PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 th | May 5, 2026 | 9.8 | 38 | NO | NO |
CVE-2024-45293HIGH PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by sl | Oct 7, 2024 | 7.5 | 31 | NO | YES |
CVE-2018-14065CRITICAL XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. | Jul 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-40902HIGH PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRow | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-40863HIGH PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does no | May 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-40296MEDIUM PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs from the origi | May 6, 2026 | 5.4 | 26 | NO | NO |
CVE-2019-12331HIGH PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This wa | Nov 7, 2019 | 8.8 | 26 | NO | NO |
CVE-2024-45291HIGH PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When | Oct 7, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-35453MEDIUM PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 th | May 5, 2026 | 5.4 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpoffice Project.
Media articles that mention a CVE ID that affects a product developed by Phpoffice Project — matched by CVE ID, not by vendor name.