phpoffice/phpexcel

composerv1.8.2deprecated

PHPExcel - OpenXML - Read, Create and Write Spreadsheet documents in PHP - Spreadsheet engine

License LGPL-2.1weak copyleft9 versions4 maintainers4 deps
PHPOffice/PHPExcel
0
/ 100
Health
find alternative

phpoffice/phpexcel is deprecated — find an alternative

Update to >= 2.3.5 to fix known vulnerabilities

  • Low health score (0/100)
  • 9 high severity vulnerabilities
  • Package is deprecated
Health breakdown0 – 100
0/25
maintenance
0/20
popularity
0/25
security
6/15
maturity
0/15
community
Vulnerabilities
19
9 high10 medium
Advisories (19)
SeverityIDSummaryFixed in
mediumCVE-2020-7776Cross-site scripting in phpoffice/phpspreadsheet1.16.0
highCVE-2024-45290PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file2.1.1
highCVE-2024-45293XXE in PHPSpreadsheet's XLSX reader2.1.1
mediumCVE-2025-22131Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet2.3.6
highCVE-2024-48917XXE in PHPSpreadsheet's XLSX reader3.4.0
highCVE-2024-56366PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file2.3.5
highCVE-2024-45048XXE in PHPSpreadsheet encoding is returned2.1.1
mediumCVE-2024-56411PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header2.3.5
highCVE-2024-56409PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file2.3.5
highCVE-2024-56365PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class2.3.5
highCVE-2024-47873XmlScanner bypass leads to XXE3.4.0
mediumCVE-2024-56412PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters2.3.5
mediumCVE-2025-23210PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters2.1.8
mediumCVE-2024-45292PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks2.1.1
mediumCVE-2024-45060PhpSpreadsheet has an Unauthenticated Cross-Site-Scripting (XSS) in sample file2.1.1
mediumCVE-2024-45291PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled2.1.1
mediumCVE-2024-45046PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information1.29.1
mediumCVE-2024-56410PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties2.3.5
highCVE-2024-56408PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file2.3.5
Threat intelligence
1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.
Maintainer trust
Active maintainers (3m)
1
Contributors (12m)
0
Primary author dominance
0%
GitHub stars
11,381
single active maintainer 3marchived repo

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/composer/phpoffice/phpexcel

Last updated · 2018-11-22T23:07:24+00:00

phpoffice/phpexcel — Health Score 0/100 | DepScope