Product
CVE-2025-22131 is a stored cross-site scripting vulnerability in PHPOffice PhpSpreadsheet caused by improper sanitization of XLSX sheet names in navigation HTML, allowing for session cookie theft.