CVE-2026-40296Disclosure(phpoffice / phpspreadsheet)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs from the original value. When a cell has a custom number format containing the text placeholder @ along with any additional literal characters (for example ". @", "@ ", or "x@"), the formatter replaces @ with the cell value and adds the extra characters, causing the formatted value to differ from the original and bypassing HTML escaping entirely. An attacker who can control the cell value and number format of an uploaded spreadsheet that is later converted to HTML and displayed to other users can achieve stored cross-site scripting. This issue is fixed in versions 5.7.0, 3.10.5, 2.4.5, 2.1.16, and 1.30.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • phpspreadsheet

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-30); latest day: 3
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
phpspreadsheet

Deep dive

Activity timeline8 mentions / 3d
01223Mentions · 2026-04-29: 2Mentions · 2026-04-30: 3Mentions · 2026-05-07: 3Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 2Technical Details · 2026-05-07: 304-2904-3005-07
Signal classification2 categories
Disclosure
675.0%
General
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure2
2026-04-303
Disclosure2General1
2026-05-073
Disclosure2General1
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-40296 · 5.6.0 → 9.8 TL;DR A critical stored XSS vulnerability in PhpSpreadsheet (CVSS 9.8) allows attackers to inject malicious JavaScript into applications by exploiting a conditional HTML-escaping flaw.

    Post summary

    A critical stored XSS vulnerability (CVE‑2026‑40296) in PhpSpreadsheet (CVSS 9.8) permits malicious JavaScript injection via a conditional HTML‑escaping flaw.

    1000029
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    PhpOffice's PhpSpreadsheet, a widely-used PHP library for reading and writing Excel files, contains a logic flaw in its HTML writer that completely bypasses HTML entity encoding under specific conditions. The vulnerability (CVE-2026-40296) affects all versions up to 5.6.0…

    Post summary

    A logic flaw in PhpSpreadsheet's HTML writer allows bypass of HTML entity encoding in all versions up to 5.6.0, marking it as a disclosed vulnerability.

    1000024
    128 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40296 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs … https://www.cve.org/CVERecord?id=CVE-2026-40296 ----- Traducción: CVE-2026-40296 Php… http://infoflow.cloud`

    Post summary

    The notice reports CVE‑2026‑40296, highlighting a PhpSpreadsheet issue where the HTML writer fails to escape characters, potentially enabling XSS; no PoC, exploit, or patch is mentioned.

    0000037
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40296 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs … https://www.cve.org/CVERecord?id=CVE-2026-40296

    Post summary

    The post shares a short technical detail about CVE-2026-40296 in PhpSpreadsheet—namely a missing htmlspecialchars escape in the HTML writer—and links to the CVE record, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000179
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40296 Stored Cross-Site Scripting in PhpSpreadsheet HTML Writer via Custom Num... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40296 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2026-40296, a stored XSS flaw in PhpSpreadsheet, and directs readers to detailed vulnerability and notification links.

    0000067
    4.0K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/2026-04-29-phpspreadsheet-cve-2026-40296-xss #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content lists a URL and several hashtags but provides no concrete details about the CVE’s exploitation, patch status, or technical characteristics.

    0000021
    128 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PhpSpreadsheet, #HTML Escaping Bypass, #CVE-2026-40296 (Critical) https://dailycve.com/phpspreadsheet-html-escaping-bypass-cve-2026-40296-critical/

    Post summary

    CVE-2026-40296 for PhpSpreadsheet is disclosed as a critical HTML escaping bypass vulnerability.

    0000036
    187 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 PhpSpreadsheet, XSS, #CVE-2026-40296 (Moderate) https://dailycve.com/phpspreadsheet-xss-cve-2026-40296-moderate/

    Post summary

    The tweet announces CVE-2026-40296, an XSS vulnerability in PhpSpreadsheet, rating it as moderate severity.

    0000032
    187 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpofficephpspreadsheet---

Explore more