CWE-1236
308 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via t...Show more |
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection. |
1Crmperks 1Database For Contact Form 7, Wpforms, Elementor Forms Jun 17, 2026 Jan 16, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection. |
1Sesami 1Cash Point & Transport Optimizer Jun 17, 2026 Dec 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. |
1Sesami 1Cash Point & Transport Optimizer Jun 17, 2026 Dec 29, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. |
1Sesami 1Cash Point & Transport Optimizer Jun 17, 2026 Dec 29, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. |
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times. |
csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection. |
1Phpjabbers 1Availability Booking Calendar Jun 17, 2026 Dec 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. |
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. |
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section,...Show more |
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory...Show more |
1Patrickrobrecht 1Posts And Users Stats Jun 17, 2026 Nov 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS Exporter.This issue affects Simple CSV/XLS Exporter: from n/a through 1.5.8. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane Emails & Newsletters with Jackmail.This issue affects Emails & Newsletters with Jackmail: from n/a through 1.2.22. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerc...Show more |
1Narolainfotech 1Export Users Data Distinct Jun 17, 2026 Nov 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3. |
Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5. |