phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 04 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Feb 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | Bypass XSS sanitizer using the javascript protocol and special characters in phpoffice/phpspreadsheet | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-03T21:14:57.255Z
Updated: 2025-02-04T15:33:39.661Z
Reserved: 2025-01-13T17:15:41.051Z
Link: CVE-2025-23210

Updated: 2025-02-04T15:25:29.732Z

Status : Received
Published: 2025-02-03T22:15:28.187
Modified: 2025-02-03T22:15:28.187
Link: CVE-2025-23210

No data.