CWE-1236
308 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File |
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloa...Show more |
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, ma...Show more |
1Ibm 1Watson Knowledge Catalog On Cloud Pak For Data Jun 17, 2026 Jul 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IB...Show more |
Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3. |
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote co...Show more |
Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9. |
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. |
1Wpmet 1Metform Elementor Contact Form Builder Jun 17, 2026 Jun 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV fil...Show more |
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting...Show more |
1Pimcore 1Customer Management Framework Jun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. |
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. |
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a craf...Show more |
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. |
1Sap 4Abap Platform Application Interface FrameworkBasis+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can i...Show more |
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inser...Show more |
1Ibm 2Maximo Application Suite Maximo Asset ManagementJun 17, 2026 Jan 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335. |
1Wecube Platform Project 1Wecube Platform Jun 17, 2026 Jan 1, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] pag...Show more |
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modific...Show more |
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during...Show more |