CVE-2024-47873: Phpoffice Phpspreadsheet

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. However, prior to versions 1.9.4, 2.1.3, 2.3.2, and 3.4.0, the regexes used in the `scan` method and the findCharSet method can be bypassed by using UCS-4 and encoding guessing. An attacker can bypass the sanitizer and achieve an XML external entity attack. Versions 1.9.4, 2.1.3, 2.3.2, and 3.4.0 fix the issue.

Affected products

  • Phpoffice Phpspreadsheet: before 1.29.4 (fixed in 1.29.4); from 2.0.0, before 2.1.3 (fixed in 2.1.3); from 2.2.0, before 2.3.2 (fixed in 2.3.2); from 3.3.0, before 3.4.0 (fixed in 3.4.0)

Published 2024-11-18. Last modified 2026-06-17.