← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Raidenmaild
1Raidenmaild
Jun 17, 2026
Nov 29, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow...Show more
A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or disrupt service on the user side.Show less
1Event Registration Application Project
1Event Registration Application
Jun 17, 2026
Nov 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code...Show more
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
1Wpforms
1Wpforms Pro
Jun 17, 2026
Nov 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
1Activity Log Project
1Activity Log
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
1Codection
1Import And Export Users And Customers
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
1Fluentforms
1Contact Form
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 22...Show more
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."Show less
1Phppointofsale
1Php Point Of Sale
Jun 17, 2026
Oct 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
1Bestwebsoft
1Post To Csv
Jun 17, 2026
Oct 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
1Zktec
1Zkbio Time
Jun 17, 2026
Sep 29, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload inj...Show more
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.Show less
1Apasionados
1Export Post Info
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress.
1Espocrm
1Espocrm
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV fi...Show more
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.Show less
1Wpaffiliatemanager
1Affiliates Manager
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the da...Show more
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the dataShow less
1Mobileeventsmanager
1Mobile Events Manager
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulner...Show more
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.Show less
1Wp Users Exporter Project
1Wp Users Exporter
Jun 17, 2026
Sep 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscr...Show more
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like First Names that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Ultimatesmsnotifications
1Ultimate Sms Notifications For Woocommerce
Jun 17, 2026
Sep 6, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated...Show more
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.Show less
1Emarketdesign
1Request A Quote
Jun 17, 2026
Jul 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin downloa...Show more
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open itShow less
1Exports And Reports Project
1Exports And Reports
Jun 17, 2026
Jul 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak dat...Show more
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.Show less
1Inventree Project
1Inventree
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.