← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Customer Management Framework
Jun 17, 2026
May 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.
1Rosariosis
1Rosariosis
Jun 17, 2026
May 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
1Churchcrm
1Churchcrm
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a craf...Show more
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.Show less
1Alf
1Alf
Jun 17, 2026
Apr 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
1Sap
4Abap Platform
Application Interface FrameworkBasis+1 more
Jun 17, 2026
Apr 11, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can i...Show more
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application. Show less
1Fortinet
1Fortianalyzer
Jun 17, 2026
Mar 7, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inser...Show more
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names.Show less
1Ibm
2Maximo Application Suite
Maximo Asset Management
Jun 17, 2026
Jan 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.
1Wecube Platform Project
1Wecube Platform
Jun 17, 2026
Jan 1, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] pag...Show more
An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page.Show less
1Arubanetworks
2Arubaos
Sd Wan
Jun 17, 2026
Dec 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modific...Show more
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system. Show less
1Dwbooster
1Appointment Hour Booking
Jun 17, 2026
Nov 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during...Show more
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Raidenmaild
1Raidenmaild
Jun 17, 2026
Nov 29, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow...Show more
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or disrupt service on the user side.Show less
1Event Registration Application Project
1Event Registration Application
Jun 17, 2026
Nov 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code...Show more
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
1Wpforms
1Wpforms Pro
Jun 17, 2026
Nov 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
1Activity Log Project
1Activity Log
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
1Codection
1Import And Export Users And Customers
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
1Fluentforms
1Contact Form
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 22...Show more
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."Show less
1Phppointofsale
1Php Point Of Sale
Jun 17, 2026
Oct 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
1Bestwebsoft
1Post To Csv
Jun 17, 2026
Oct 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection