CVE-2026-40296 | PHPOffice PhpSpreadsheet up to 5.6.0 Placeholder cross site scripting (GHSA-hrmw-qprp-wgmc)
A vulnerability described as problematic has been identified in PHPOffice PhpSpreadsheet up to 1.30.3/2.1.15/2.4.4/3.10.4/5.6.0. The affected element is an unknown function of the component Placeholder Handler. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-40296. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.