<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:38:54.072148+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01639</id>
    <title>bdu:2025-01639</title>
    <updated>2026-10-04T15:38:54.138340+00:00</updated>
    <content>bdu:2025-01639</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-211161</id>
    <title>EUVD-2026-211161</title>
    <updated>2026-10-04T15:38:54.138377+00:00</updated>
    <content>EUVD-2026-211161</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-211161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22131</id>
    <title>fkie_cve-2025-22131</title>
    <updated>2026-10-04T15:38:54.138392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-22131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-79xx-vf93-p7cx</id>
    <title>GHSA-79xx-vf93-p7cx — Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet</title>
    <updated>2026-10-04T15:38:54.138421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: phpoffice/phpspreadsheet, Packagist: phpoffice/phpexcel</p>
<p>### Summary
The researcher discovered zero-day vulnerability Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.</p>
<p>### Details
When generating the HTML from an xlsx file containing multiple sheets, a navigation menu is created. This menu includes the sheet names, which are not sanitized. As a result, an attacker can exploit this vulnerability to execute JavaScript code.</p>
<p>```php
        // Construct HTML
        $html = '';</p>
<p>// Only if there are more than 1 sheets
        if (count($sheets) &gt; 1) {
            // Loop all sheets
            $sheetId = 0;</p>
<p>$html .= '&lt;ul class="navigation"&gt;' . PHP_EOL;</p>
<p>foreach ($sheets as $sheet) {
                $html .= '  &lt;li class="sheet' . $sheetId . '"&gt;&lt;a href="#sheet' . $sheetId . '"&gt;' . $sheet-&gt;getTitle() . '&lt;/a&gt;&lt;/li&gt;' . PHP_EOL;
                ++$sheetId;
            }</p>
<p>$html .= '&lt;/ul&gt;' . PHP_EOL;
        }
```</p>
<p>### PoC
1. Create an XLSX file with multiple sheets : 
![image](https://github.com/user-attachments/assets/e3fc027a-9525-4d7f-b107-cfa6e78d04e7)</p>
<p>2. Generate the HTML content 
```php
&lt;?php
	require __DIR__ . '/vendor/autoload.php';</p>
<p>$inputFileName = 'payload.xlsx';
	$spreadsheet = \PhpOffice\PhpSpreadsheet\IOFactory::load($inputFileName);
	$writer = new \PhpOffice\PhpSpreadsheet\Writer\Html($spreadsheet);
	$writer-&gt;writeAllSheets();
	echo $writer-&gt;generateHTMLAll();
?&gt;
```
3. Enjoy
![image](h…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-79xx-vf93-p7cx"/>
  </entry>
</feed>
