Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16521 | PHPOffice Math allows XXE when processing an XML file in the MathML format |
Github GHSA |
GHSA-42hm-pq2f-3r7m | PHPOffice Math allows XXE when processing an XML file in the MathML format |
Fri, 30 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability. | |
| Title | PHPOffice Math allows XXE when processing an XML file in the MathML format | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T20:46:17.339Z
Reserved: 2025-05-27T20:14:34.296Z
Link: CVE-2025-48882
Updated: 2025-05-30T20:46:13.055Z
Status : Deferred
Published: 2025-05-30T20:15:43.527
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-48882
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA