← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zktec
1Zkbio Time
Jun 17, 2026
Sep 29, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload inj...Show more
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.Show less
1Apasionados
1Export Post Info
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress.
1Espocrm
1Espocrm
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV fi...Show more
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.Show less
1Wpaffiliatemanager
1Affiliates Manager
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the da...Show more
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the dataShow less
1Mobileeventsmanager
1Mobile Events Manager
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulner...Show more
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.Show less
1Wp Users Exporter Project
1Wp Users Exporter
Jun 17, 2026
Sep 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscr...Show more
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Ultimatesmsnotifications
1Ultimate Sms Notifications For Woocommerce
Jun 17, 2026
Sep 6, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated...Show more
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Emarketdesign
1Request A Quote
Jun 17, 2026
Jul 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin downloa...Show more
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open itShow less
1Exports And Reports Project
1Exports And Reports
Jun 17, 2026
Jul 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak dat...Show more
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.Show less
1Inventree Project
1Inventree
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
1Usabilitydynamics
1Wp Crm
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
1Kromit
1Titra
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.0 HIGH· v3
3.5 LOW· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
1Ibm
1Sevone Network Performance Management
Jun 17, 2026
Jun 7, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may...Show more
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely.Show less
1Dell
1Powerstoreos
Jun 17, 2026
Jun 2, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads tha...Show more
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.Show less
1Csv Safe Project
1Csv Safe
Jun 17, 2026
May 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
1Luya
1Yii Helpers
Jun 17, 2026
May 1, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided com...Show more
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.Show less
1Invicti
1Acunetix
Jun 17, 2026
Apr 19, 2022
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
1Eaton
1Intelligent Power Manager
Jun 17, 2026
Apr 18, 2022
N/A· v4
8.0 HIGH· v3
7.9 HIGH· v2
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure...Show more
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vulnerable to CSV Formula Injection. This issue affects: Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) all version 1.5.0plus205 and prior versions.Show less
1Mantisbt
1Mantisbt
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.8 HIGH· v3
6.0 MEDIUM· v2
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in...Show more
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.Show less
1Vfbpro
1Visual Form Builder
Jun 17, 2026
Apr 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible...Show more
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less