Exceljs
Exceljs · 5 CVEs
CVE-2026-78209
HIGH
exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values
Aug 24, 2026
CVE-2026-78208
HIGH
exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename
Aug 24, 2026
CVE-2026-78207
CRITICAL
exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization
Aug 24, 2026
CVE-2026-78206
HIGH
exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
Aug 24, 2026
CVE-2018-16459
MEDIUM
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
Sep 6, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-78209 | exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values | HIGH | 0.41% | Aug 24, 2026 |
| CVE-2026-78208 | exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename | HIGH | 0.51% | Aug 24, 2026 |
| CVE-2026-78207 | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization | CRITICAL | 0.60% | Aug 24, 2026 |
| CVE-2026-78206 | exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression | HIGH | 0.63% | Aug 24, 2026 |
| CVE-2018-16459 | An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser. | MEDIUM | 0.76% | Sep 6, 2018 |
Showing 1 to 5 of 5 CVEs