CVE security advisories and vulnerability history for phpspreadsheet by phpoffice.
27
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
23
Public exploits
With known exploit
6.8
Avg CVSS
2018–2026
Last updated
Overview
phpoffice phpspreadsheet has 27 published CVE records since 2018, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 23 have a known public exploit. The average CVSS base score across scored CVEs is 6.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting phpoffice phpspreadsheet, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of phpoffice phpspreadsheet's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High14
Medium10
Low0
2 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of phpoffice phpspreadsheet's CVEs are currently listed in CISA's KEV catalog.
Public exploits
23
23 of phpoffice phpspreadsheet's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every phpoffice phpspreadsheet version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about phpoffice phpspreadsheet vulnerabilities.
How many CVEs does phpoffice phpspreadsheet have?
phpoffice phpspreadsheet has 27 published CVE records since 2018.
How many phpoffice phpspreadsheet CVEs are in CISA KEV?
None of phpoffice phpspreadsheet's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for phpoffice phpspreadsheet vulnerabilities?
Yes — 23 of phpoffice phpspreadsheet's CVEs have a known public exploit.
Which versions of phpoffice phpspreadsheet are affected?
196 distinct phpoffice phpspreadsheet versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in phpoffice phpspreadsheet CVEs?
phpoffice phpspreadsheet's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-611 (Improper Restriction of XML External Entity Reference), CWE-918 (Server-Side Request Forgery (SSRF)), CWE-770 (Allocation of Resources Without Limits or Throttling).
How many critical phpoffice phpspreadsheet vulnerabilities are there?
phpoffice phpspreadsheet has 1 critical and 14 high-severity CVEs.
What is the average severity of phpoffice phpspreadsheet CVEs?
The average CVSS base score across phpoffice phpspreadsheet's scored CVEs is 6.8.