CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected. |
2Oracle Sheetjs3Rest Data Services SheetjsSheetjs ProJun 17, 2026 Jul 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js. |