phpoffice/phpspreadsheet vulnerabilities
CVEs whose affected-version data names the phpoffice/phpspreadsheet package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-59931High· 7.7PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.37%via GHSA
CVE-2026-59932High· 7.5PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.38%via GHSA
CVE-2026-59933High· 7.5PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.38%via GHSA
CVE-2026-45034CriticalPoCPHPSpreadsheet has a patch bypass for CVE-2026-34084
PHPSpreadsheet has a patch bypass for CVE-2026-34084
▾ Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA