← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Koha
1Koha
Jun 17, 2026
Feb 12, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via t...Show more
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.Show less
1Ncr
1Terminal Handler
Jun 17, 2026
Feb 6, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
1Crmperks
1Database For Contact Form 7, Wpforms, Elementor Forms
Jun 17, 2026
Jan 16, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
1Sesami
1Cash Point & Transport Optimizer
Jun 17, 2026
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
1Sesami
1Cash Point & Transport Optimizer
Jun 17, 2026
Dec 29, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
1Sesami
1Cash Point & Transport Optimizer
Jun 17, 2026
Dec 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
1Activeadmin
1Activeadmin
Jun 17, 2026
Dec 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.
1Activeadmin
1Active Admin
Jun 17, 2026
Dec 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.
1Phpjabbers
1Availability Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
1Ibm
1Security Guardium
Jun 17, 2026
Nov 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
1Corebos
1Corebos
Jun 17, 2026
Nov 17, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section,...Show more
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer.Show less
1Wpwax
1Directorist
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory...Show more
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.Show less
1Patrickrobrecht
1Posts And Users Stats
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Patrick Robrecht Posts and Users Stats.This issue affects Posts and Users Stats: from n/a through 1.1.3.
1Shambix
1Simple Csv/xls Exporter
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS Exporter.This issue affects Simple CSV/XLS Exporter: from n/a through 1.5.8.
1Kaushikkalathiya
1Export Users Data
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.
1Kigurumi
1Csv Exporter
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0.
1Jackmail
1Jackmail
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane Emails & Newsletters with Jackmail.This issue affects Emails & Newsletters with Jackmail: from n/a through 1.2.22.
1Wpdeveloper
1Reviewx
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerc...Show more
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.Show less
1Narolainfotech
1Export Users Data Distinct
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
1Noptin
1Noptin
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.