<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:00:43 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01639</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01639</link>
      <description>bdu:2025-01639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01639</guid>
    </item>
    <item>
      <title>EUVD-2026-211161</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211161</link>
      <description>EUVD-2026-211161</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211161</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22131</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22131</link>
      <description>&lt;p&gt;PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22131</guid>
    </item>
    <item>
      <title>GHSA-79xx-vf93-p7cx — Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-79xx-vf93-p7cx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpoffice/phpspreadsheet, Packagist: phpoffice/phpexcel&lt;/p&gt;
&lt;p&gt;### Summary
The researcher discovered zero-day vulnerability Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.&lt;/p&gt;
&lt;p&gt;### Details
When generating the HTML from an xlsx file containing multiple sheets, a navigation menu is created. This menu includes the sheet names, which are not sanitized. As a result, an attacker can exploit this vulnerability to execute JavaScript code.&lt;/p&gt;
&lt;p&gt;```php
        // Construct HTML
        $html = &amp;#39;&amp;#39;;&lt;/p&gt;
&lt;p&gt;// Only if there are more than 1 sheets
        if (count($sheets) &amp;gt; 1) {
            // Loop all sheets
            $sheetId = 0;&lt;/p&gt;
&lt;p&gt;$html .= &amp;#39;&amp;lt;ul class=&amp;#34;navigation&amp;#34;&amp;gt;&amp;#39; . PHP_EOL;&lt;/p&gt;
&lt;p&gt;foreach ($sheets as $sheet) {
                $html .= &amp;#39;  &amp;lt;li class=&amp;#34;sheet&amp;#39; . $sheetId . &amp;#39;&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;#sheet&amp;#39; . $sheetId . &amp;#39;&amp;#34;&amp;gt;&amp;#39; . $sheet-&amp;gt;getTitle() . &amp;#39;&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#39; . PHP_EOL;
                ++$sheetId;
            }&lt;/p&gt;
&lt;p&gt;$html .= &amp;#39;&amp;lt;/ul&amp;gt;&amp;#39; . PHP_EOL;
        }
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create an XLSX file with multiple sheets : 
![image](https://github.com/user-attachments/assets/e3fc027a-9525-4d7f-b107-cfa6e78d04e7)&lt;/p&gt;
&lt;p&gt;2. Generate the HTML content 
```php
&amp;lt;?php
	require __DIR__ . &amp;#39;/vendor/autoload.php&amp;#39;;&lt;/p&gt;
&lt;p&gt;$inputFileName = &amp;#39;payload.xlsx&amp;#39;;
	$spreadsheet = \PhpOffice\PhpSpreadsheet\IOFactory::load($inputFileName);
	$writer = new \PhpOffice\PhpSpreadsheet\Writer\Html($spreadsheet);
	$writer-&amp;gt;writeAllSheets();
	echo $writer-&amp;gt;generateHTMLAll();
?&amp;gt;
```
3. Enjoy
![image](h…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpoffice/phpspreadsheet, Packagist: phpoffice/phpexcel&lt;/p&gt;
&lt;p&gt;### Summary
The researcher discovered zero-day vulnerability Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.&lt;/p&gt;
&lt;p&gt;### Details
When generating the HTML from an xlsx file containing multiple sheets, a navigation menu is created. This menu includes the sheet names, which are not sanitized. As a result, an attacker can exploit this vulnerability to execute JavaScript code.&lt;/p&gt;
&lt;p&gt;```php
        // Construct HTML
        $html = &amp;#39;&amp;#39;;&lt;/p&gt;
&lt;p&gt;// Only if there are more than 1 sheets
        if (count($sheets) &amp;gt; 1) {
            // Loop all sheets
            $sheetId = 0;&lt;/p&gt;
&lt;p&gt;$html .= &amp;#39;&amp;lt;ul class=&amp;#34;navigation&amp;#34;&amp;gt;&amp;#39; . PHP_EOL;&lt;/p&gt;
&lt;p&gt;foreach ($sheets as $sheet) {
                $html .= &amp;#39;  &amp;lt;li class=&amp;#34;sheet&amp;#39; . $sheetId . &amp;#39;&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;#sheet&amp;#39; . $sheetId . &amp;#39;&amp;#34;&amp;gt;&amp;#39; . $sheet-&amp;gt;getTitle() . &amp;#39;&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#39; . PHP_EOL;
                ++$sheetId;
            }&lt;/p&gt;
&lt;p&gt;$html .= &amp;#39;&amp;lt;/ul&amp;gt;&amp;#39; . PHP_EOL;
        }
```&lt;/p&gt;
&lt;p&gt;### PoC
1. Create an XLSX file with multiple sheets : 
![image](https://github.com/user-attachments/assets/e3fc027a-9525-4d7f-b107-cfa6e78d04e7)&lt;/p&gt;
&lt;p&gt;2. Generate the HTML content 
```php
&amp;lt;?php
	require __DIR__ . &amp;#39;/vendor/autoload.php&amp;#39;;&lt;/p&gt;
&lt;p&gt;$inputFileName = &amp;#39;payload.xlsx&amp;#39;;
	$spreadsheet = \PhpOffice\PhpSpreadsheet\IOFactory::load($inputFileName);
	$writer = new \PhpOffice\PhpSpreadsheet\Writer\Html($spreadsheet);
	$writer-&amp;gt;writeAllSheets();
	echo $writer-&amp;gt;generateHTMLAll();
?&amp;gt;
```
3. Enjoy
![image](h…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-79xx-vf93-p7cx</guid>
    </item>
  </channel>
</rss>
