CVE-2026-34084 (matched: php)

  • Monday, 27th July, 2026
  • 04:03am

A security vulnerability tracked as CVE-2026-34084 has been found in PhpSpreadsheet, a popular library that many websites use to read, write, and process spreadsheet files like Excel or CSV exports. The flaw impacts multiple older versions of this tool. This issue only affects websites that both use PhpSpreadsheet and allow user-submitted input for the filename passed to the library’s file loading feature. If an attacker exploits this flaw, they could either run unauthorized malicious code on the server, or force the server to send unintended requests to external systems, which could lead to data leaks or further security problems for the site. The vulnerability has been fixed in updated versions of PhpSpreadsheet: 1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-34084

« Back