← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Nov 30, 2020
N/A· v4
9.0 CRITICAL· v3
9.0 HIGH· v2
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 1853...Show more
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.Show less
1Netskope
1Netskope
Jun 17, 2026
Nov 20, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
1Salesagility
1Suitecrm
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
1Ibm
1Filenet Content Manager
Jun 17, 2026
Nov 9, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID...Show more
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.Show less
1Bbraun
1Onlinesuite Application Package
Jun 17, 2026
Nov 6, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
1Marmind
1Marmind
Jun 17, 2026
Nov 5, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “No...Show more
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.Show less
1Mind
1Imind Server
Jun 17, 2026
Nov 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
1Jomsocial
1Jomsocial
Jun 17, 2026
Nov 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
1Phpmyadmin
1Phpmyadmin
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
1Codection
1Import And Export Users And Customers
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
1Weformspro
1Weforms
Jun 17, 2026
Nov 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
1Easyregistrationforms
1Easy Registration Forms
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, ther...Show more
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.Show less
1Getgophish
1Gophish
Jun 17, 2026
Oct 28, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
1Anuko
1Time Tracker
Jun 17, 2026
Oct 16, 2020
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value...Show more
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Oct 12, 2020
N/A· v4
6.8 MEDIUM· v3
8.5 HIGH· v2
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
1Ibm
1Cognos Analytics
Jun 17, 2026
Oct 12, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploi...Show more
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.Show less
1Ozeki
1Ozeki Ng Sms Gateway
Jun 17, 2026
Sep 22, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
5.0 MEDIUM· v3
5.8 MEDIUM· v2
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special e...Show more
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.Show less
1I Doit
1I Doit
Jun 17, 2026
Aug 20, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
1Redhat
1Cloudforms Management Engine
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.3 MEDIUM· v3
4.9 MEDIUM· v2
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering...Show more
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.Show less