CWE-1236
298 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (298)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pimcore 1Customer Management Framework Jun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. |
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. |
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a craf...Show more |
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. |
1Sap 4Abap Platform Application Interface FrameworkBasis+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can i...Show more |
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inser...Show more |
1Ibm 2Maximo Application Suite Maximo Asset ManagementJun 17, 2026 Jan 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335. |
1Wecube Platform Project 1Wecube Platform Jun 17, 2026 Jan 1, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] pag...Show more |
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modific...Show more |
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during...Show more |
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow...Show more |
1Event Registration Application Project 1Event Registration Application Jun 17, 2026 Nov 21, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code...Show more |
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. |
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. |
1Activity Log Project 1Activity Log Jun 17, 2026 Nov 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress. |
1Codection 1Import And Export Users And Customers Jun 17, 2026 Nov 7, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files. |
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 3, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 22...Show more |
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
|
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection |