Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sheetjs

First CVE: Jul 19, 2021Active for: 5 yearsTotal CVEs: 4

SheetJS develops a JavaScript spreadsheet-parsing and generation library widely embedded in web applications and data-processing pipelines, with vulnerabilities centering on its core product and derived commercial variant. The observed weakness classes—prototype pollution and uncontrolled resource consumption—reflect the parsing and object-manipulation risks inherent to a dynamic-language library handling untrusted spreadsheet input, and are characteristic attack surfaces for this class of utility library. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 56% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sheetjs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2021
5 years ago
Most Recent CVE
Apr 24, 2023
1,187 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-30533HIGH
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
Apr 24, 20237.820NONO
CVE-2021-32014MEDIUM
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.
Jul 19, 20215.520NONO
CVE-2021-32013MEDIUM
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issu
Jul 19, 20215.520NONO
CVE-2021-32012MEDIUM
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issu
Jul 19, 20215.520NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
75%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required4 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sheetjs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sheetjs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sheetjs's Products

View all 1 CNAs →

Top CWEs