VYPR
High severityNVD Advisory· Published May 30, 2025· Updated Apr 15, 2026

CVE-2025-48882

CVE-2025-48882

Description

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard libxml extension and the LIBXML_DTDLOAD flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
phpoffice/mathPackagist
< 0.3.00.3.0

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.