Package impact
Packagist / phpoffice/phpspreadsheet
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2026-40296 | medium | 5.4 | 5.4 | 29d ago | PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer | |
| CVE-2026-35453 | medium | 5.4 | 5.4 | 29d ago | PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer |