Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-0222 | phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability. | 
|  Github GHSA | GHSA-r57h-547h-w24f | PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 04 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 03 Feb 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the javascript protocol and special characters. This issue has been addressed in versions 3.9.0, 2.3.7, 2.1.8, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Bypass XSS sanitizer using the javascript protocol and special characters in phpoffice/phpspreadsheet | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-04T15:33:39.661Z
Reserved: 2025-01-13T17:15:41.051Z
Link: CVE-2025-23210
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-04T15:25:29.732Z
 NVD
                        NVD
                    Status : Received
Published: 2025-02-03T22:15:28.187
Modified: 2025-02-03T22:15:28.187
Link: CVE-2025-23210
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-07-12T15:26:17Z