Junglewise Threat Intelligence

CVE-2026-35453: PHPOffice PhpSpreadsheet XSS in HTML Writer via NumberFormat

CVE-2026-35453 · Severity: medium · CVSS 5.4 · Published 2026-05-05

Technologies: Phpoffice Phpspreadsheet. Vendors: Phpoffice.

Executive brief

PhpSpreadsheet is a popular software library used by web applications to read and generate spreadsheet files like Excel. A security flaw in its HTML export feature allows an attacker to embed malicious scripts within a spreadsheet. If a user views the resulting HTML page generated by the library, the attacker could steal session information or perform unauthorized actions on the user's behalf.

Technical details

A cross-site scripting (XSS) vulnerability exists in the PhpSpreadsheet HTML Writer. The root cause is a failure to apply htmlspecialchars() escaping when a cell uses a custom number format containing the '@' text placeholder combined with literal text (e.g., '@ "items"'). In these cases, the formatter substitutes the raw cell value into the format string and returns early, bypassing the escaping callback. An attacker with the ability to control cell content can inject arbitrary HTML and JavaScript into the generated output. The issue is fixed in versions 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0.

Affected products

  • PHPOffice PhpSpreadsheet <= 1.30.3, 2.0.0 - 2.1.15, 2.2.0 - 2.4.4, 3.3.0 - 3.10.4, 4.0.0 - 5.6.0

Timeline

  • 2026-04-26: advisory: GitHub Advisory GHSA-6wpp-88cp-7q68 published
  • 2026-05-05: disclosed: CVE-2026-35453 published

References

Related threats