← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Umbrella
Jun 17, 2026
Apr 8, 2021
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected de...Show more
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Ciphercoin
1Contact Form 7 Database Addon
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
1Bigprof
1Online Invoicing System
Jun 17, 2026
Mar 3, 2021
N/A· v4
4.4 MEDIUM· v3
5.8 MEDIUM· v2
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other cli...Show more
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that the user did not have access to.Show less
1Prestashop
1Prestashop
Jun 17, 2026
Feb 26, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed i...Show more
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2Show less
1Huawei
1Manageone
Jun 17, 2026
Feb 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some p...Show more
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.Show less
1Phplist
1Phplist
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
1Huawei
1Imanager Neteco 6000
Jun 17, 2026
Dec 24, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient...Show more
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.Show less
1Solarwinds
1Webhelpdesk
Jun 17, 2026
Dec 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
1Openasset
1Digital Asset Management
Jul 9, 2026
Dec 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project informa...Show more
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.Show less
1Ibm
1Resilient Security Orchestration Automation And Response
Jun 17, 2026
Dec 11, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Nov 30, 2020
N/A· v4
9.0 CRITICAL· v3
9.0 HIGH· v2
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 1853...Show more
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.Show less
1Netskope
1Netskope
Jun 17, 2026
Nov 20, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
1Salesagility
1Suitecrm
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
1Ibm
1Filenet Content Manager
Jun 17, 2026
Nov 9, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID...Show more
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.Show less
1Bbraun
1Onlinesuite Application Package
Jun 17, 2026
Nov 6, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
1Marmind
1Marmind
Jun 17, 2026
Nov 5, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “No...Show more
A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can inject a payload into the “Description” field under the “Insert To-Do” option. Other users might download this data, for example a CSV file, and execute the malicious commands on their computer by opening the file using a software such as Microsoft Excel. The attacker could gain remote access to the user’s PC.Show less
1Mind
1Imind Server
Jun 17, 2026
Nov 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
1Jomsocial
1Jomsocial
Jun 17, 2026
Nov 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
1Phpmyadmin
1Phpmyadmin
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
1Codection
1Import And Export Users And Customers
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.