View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical exceljs Prototype Pollution Flaw (CVE-2026-78207, CVSS 9.3)

🔓 CVEs & KEV

  • CVE-2026-78207 — CVSS 9.3 — exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Ser...

  • CVE-2026-78208 — CVSS 8.7 — exceljs through 4.4.0 Path Traversal via Unvalidated addImage filenameexceljs...

  • CVE-2026-78206 — CVSS 8.7 — exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx De...

  • CVE-2026-78209 — CVSS 8.4 — exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Valuesexceljs-...

  • CVE-2026-78203 — CVSS 7.1 — Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthor...

  • CVE-2026-78205 — CVSS 6.9 — BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC ...

  • CVE-2026-78148 — CVSS 6.9 — ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer de...

  • CVE-2026-78147 — CVSS 6.9 — ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserializ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check