<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:35:02.785028+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308723</id>
    <title>EUVD-2026-308723</title>
    <updated>2026-10-06T10:35:02.840855+00:00</updated>
    <content>EUVD-2026-308723</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35453</id>
    <title>fkie_cve-2026-35453</title>
    <updated>2026-10-06T10:35:02.840900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 through 5.6.0, the HTML Writer skips htmlspecialchars() output escaping when a cell uses a custom number format containing the @ text placeholder with additional literal text (e.g., @ "items"). The escaping is only applied when the formatted output strictly equals the original cell value. When the format code contains @ with quoted literal text, the formatter substitutes the raw cell value into the format string and returns early without invoking the escaping callback. An attacker who can control cell content in a spreadsheet processed by the HTML Writer can inject arbitrary HTML and JavaScript into the generated output. This issue has been fixed in versions 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6wpp-88cp-7q68</id>
    <title>GHSA-6wpp-88cp-7q68 — PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer</title>
    <updated>2026-10-06T10:35:02.840942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: phpoffice/phpspreadsheet</p>
<p>### Summary
The HTML Writer in PhpSpreadsheet bypasses `htmlspecialchars()` output escaping when a cell uses a custom number format containing the `@` text placeholder with additional literal text (e.g., `@ "items"` or `"Total: "@`). This allows an attacker to inject arbitrary HTML and JavaScript into the generated HTML output by crafting a malicious XLSX file.</p>
<p>### Details</p>
<p>#### 1. Conditional escaping in `Html.php:1586-1594`</p>
<p>```php
$cellData = NumberFormat::toFormattedString(
    $origData2,
    $formatCode ?? NumberFormat::FORMAT_GENERAL,
    [$this, 'formatColor']
);</p>
<p>if ($cellData === $origData) {
    $cellData = htmlspecialchars($cellData, Settings::htmlEntityFlags());
}
```</p>
<p>`htmlspecialchars()` is only called when `$cellData === $origData` (strict comparison). If the formatted output differs from the original value in any way, escaping is skipped entirely.</p>
<p>#### 2. Early return in `Formatter.php:136-152`</p>
<p>```php
if (preg_match(self::SECTION_SPLIT, $format) === 0
    &amp;&amp; preg_match(self::SYMBOL_AT, $formatx) === 1) {
    if (!str_contains($format, '"')) {
        return str_replace('@', /* raw value */, $format);
    }
    return str_replace(/* ... preg_replace with raw value ... */);
}
```</p>
<p>When the format code contains `@` with additional literal text (e.g., `@ "items"`), the formatter substitutes the raw cell value into the format string and **returns early** — the `formatColor` callback (which would have applied `htmlspecialchars`) is never invoked.</p>
<p>### PoC</p>
<p>**…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6wpp-88cp-7q68"/>
  </entry>
</feed>
