PHPSpreadsheet - Read, Create and Write Spreadsheet documents in PHP - Spreadsheet engine
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10549 phpoffice/phpspreadsheet is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.0.0 - 1.29.12, 2.0.0 - 2.1.11, 2.2.0 - 2.3.10, 3.0.0 - 3.9.3 and 4.0.0 - 4.5.0. | 1.0.0 - 1.29.122.0.0 - 2.1.112.2.0 - 2.3.10 +2 more | High |
CVE-2025-23210 phpoffice/phpspreadsheet is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.9.0, 0.0.0 - 1.29.9, 2.2.0 - 2.3.7 and 2.0.0 - 2.1.8. | 0.0.0 - 1.29.92.0.0 - 2.1.82.2.0 - 2.3.7 +1 more | Medium |
CVE-2025-22131 phpoffice/phpspreadsheet is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.8.0, 0.0.0 - 1.29.8, 2.0.0 - 2.1.7 and 2.2.0 - 2.3.6. | 0.0.0 - 1.29.82.0.0 - 2.1.72.2.0 - 2.3.6 +1 more | Medium |
CVE-2024-56410 phpoffice/phpspreadsheet is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.7.0, 0.0.0 - 1.29.6, 2.0.0 - 2.1.5 and 2.2.0 - 2.3.4. | 0.0.0 - 1.29.62.0.0 - 2.1.52.2.0 - 2.3.4 +1 more | Medium |
CVE-2024-56412 phpoffice/phpspreadsheet is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.7.0, 0.0.0 - 1.29.6, 2.0.0 - 2.1.5 and 2.2.0 - 2.3.4. | 0.0.0 - 1.29.62.0.0 - 2.1.52.2.0 - 2.3.4 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
composer/pcre Version ^1||^2||^3 | — | — |
markbaker/matrix Version ^3.0 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
markbaker/complex Version ^3.0 | — | — |
maennchen/zipstream-php Version ^2.1 || ^3.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant