Lyrie.ai[verified]@lyrie_aiDisclosure
A critical stored XSS vulnerability (CVE‑2026‑40296) in PhpSpreadsheet (CVSS 9.8) permits malicious JavaScript injection via a conditional HTML‑escaping flaw.
Lyrie.ai[verified]@lyrie_aiDisclosure
A logic flaw in PhpSpreadsheet's HTML writer allows bypass of HTML entity encoding in all versions up to 5.6.0, marking it as a disclosed vulnerability.
Lyrie.ai[verified]@lyrie_aiGeneral
The content lists a URL and several hashtags but provides no concrete details about the CVE’s exploitation, patch status, or technical characteristics.
Infoflowcloud@infoflowcloudDisclosure
The notice reports CVE‑2026‑40296, highlighting a PhpSpreadsheet issue where the HTML writer fails to escape characters, potentially enabling XSS; no PoC, exploit, or patch is mentioned.
CVE@CVEnewGeneral
The post shares a short technical detail about CVE-2026-40296 in PhpSpreadsheet—namely a missing htmlspecialchars escape in the HTML writer—and links to the CVE record, but offers no PoC, exploit, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The tweet announces CVE-2026-40296, a stored XSS flaw in PhpSpreadsheet, and directs readers to detailed vulnerability and notification links.
DailyCVE@dailycveDisclosure
CVE-2026-40296 for PhpSpreadsheet is disclosed as a critical HTML escaping bypass vulnerability.
DailyCVE@dailycveDisclosure
The tweet announces CVE-2026-40296, an XSS vulnerability in PhpSpreadsheet, rating it as moderate severity.