← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Givewp
1Givewp
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
1Webtoffee
1Product Reviews Import Export For Woocommerce
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8.
1Lenderd
11003 Mortgage Application
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application.This issue affects 1003 Mortgage Application: from n/a through 1.75.
1Ayecode
1Userswp
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
1Simple History
1Simple History
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History – user activity log, audit tool.This issue affects Simple History – user activity log, audit tool: from n/a through...Show more
Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History – user activity log, audit tool.This issue affects Simple History – user activity log, audit tool: from n/a through 3.3.1.Show less
1Dell
1Smartfabric Storage Software
Jun 17, 2026
Oct 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote...Show more
Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type attacks. Show less
1Searchblox
1Searchblox
Jun 17, 2026
Sep 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Aug 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 2...Show more
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.Show less
1Atlos
1Atlos
Jun 17, 2026
Aug 17, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the description field in the incident function.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Jul 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
1Tadirantele
1Aeonix
Jun 17, 2026
Jul 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
1Nokia
1Netact
Jun 17, 2026
Jul 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloa...Show more
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.Show less
1Avaya
1Call Management System
Jun 17, 2026
Jul 18, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, ma...Show more
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.   Show less
1Ibm
1Watson Knowledge Catalog On Cloud Pak For Data
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IB...Show more
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.Show less
1Fossbilling
1Fossbilling
Jun 17, 2026
Jun 30, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.
1Ericsson
1Network Manager
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote co...Show more
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need admin/elevated access to exploit the vulnerability.Show less
1Admidio
1Admidio
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.
1Sage
1X3
Jul 9, 2026
Jun 22, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
1Wpmet
1Metform Elementor Contact Form Builder
Jun 17, 2026
Jun 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV fil...Show more
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Minical
1Minical
Jun 17, 2026
Jun 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting...Show more
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file.Show less