CVE-2025-22131
20.01.2025, 16:15
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.
Vendor | Product | Version |
---|---|---|
phpoffice | phpspreadsheet | 𝑥 < 1.29.8 |
phpoffice | phpspreadsheet | 2.0.0 ≤ 𝑥 < 2.1.7 |
phpoffice | phpspreadsheet | 2.2.0 ≤ 𝑥 < 2.3.6 |
phpoffice | phpspreadsheet | 3.0.0 ≤ 𝑥 < 3.8.0 |
𝑥
= Vulnerable software versions