23 vulnerabilities across 14 products scored HIGH or above on June 22, 2026.
🔴 CRITICAL: 1 🟠 HIGH: 22 🔴 [CRITICAL] phpoffice/phpspreadsheet 1 CVE | CVSS 4.0: 9.2 | AAS 12.5
cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* PHPOffice PhpSpreadsheet, a widely used PHP library for reading and writing spreadsheet files, is affected by a critical severity vulnerability (CVE-2026-45034, CVSS 9.2) that bypasses a prior security fix for stream wrapper restrictions. An attacker can craft malicious file paths with additional slashes to evade the wrapper prohibition check, potentially enabling exploitation through dangerous PHP stream wrappers such as phar://, php://, or expect://. A functional exploit is available, making this an urgent priority for any team running applications that use PhpSpreadsheet to process user-supplied files.
...