← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Puppet
1Puppet Enterprise
Jun 17, 2026
Aug 30, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
1Pimcore
1Pimcore
Jun 17, 2026
Aug 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch...Show more
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Aug 9, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse s...Show more
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.Show less
1Schneider Electric
1Easergy T300 Firmware
Jun 17, 2026
Jul 21, 2021
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
1Bookingcore
1Booking Core
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in ba...Show more
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.Show less
1Fetchdesigns
1Sign Up Sheets
Jun 17, 2026
Jul 12, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
1Akaunting
1Akaunting
Jun 17, 2026
Jun 21, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
1Blackberry
1Unified Endpoint Management
Jun 17, 2026
May 13, 2021
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet app...Show more
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.Show less
1Ibm
1Spectrum Scale
Jun 17, 2026
Apr 27, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file c...Show more
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.Show less
1Cisco
1Umbrella
Jun 17, 2026
Apr 8, 2021
N/A· v4
4.1 MEDIUM· v3
3.5 LOW· v2
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected de...Show more
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Umbrella
Jun 17, 2026
Apr 8, 2021
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected de...Show more
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Ciphercoin
1Contact Form 7 Database Addon
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
1Bigprof
1Online Invoicing System
Jun 17, 2026
Mar 3, 2021
N/A· v4
4.4 MEDIUM· v3
5.8 MEDIUM· v2
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other cli...Show more
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.Show less
1Prestashop
1Prestashop
Jun 17, 2026
Feb 26, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed i...Show more
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2Show less
1Huawei
1Manageone
Jun 17, 2026
Feb 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some p...Show more
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.Show less
1Phplist
1Phplist
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
1Huawei
1Imanager Neteco 6000
Jun 17, 2026
Dec 24, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient...Show more
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.Show less
1Solarwinds
1Webhelpdesk
Jun 17, 2026
Dec 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
1Openasset
1Digital Asset Management
Jul 9, 2026
Dec 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project informa...Show more
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.Show less
1Ibm
1Resilient Security Orchestration Automation And Response
Jun 17, 2026
Dec 11, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.