CWE-1236
298 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (298)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. |
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area. |
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature. |
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=g...Show more |
1Search Meter Project 1Search Meter Jun 17, 2026 Apr 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=searc...Show more |
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, a...Show more |
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, a...Show more |
1Zohocorp 1Manageengine Password Manager Pro Jun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this...Show more |
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data. |
1Codepeople 1Appointment Booking Calendar Jun 17, 2026 Mar 4, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab...Show more |
1Export Users To Csv Project 1Export Users To Csv Jun 17, 2026 Feb 28, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection. |
LiteCart through 2.2.1 allows CSV injection via a customer's profile. |
KeePass 2.4.1 allows CSV injection in the title field of a CSV export. |
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file...Show more |
1Solarwinds 1Serv U Ftp Server Jun 17, 2026 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. |
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection. |
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-...Show more |
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informationa...Show more |
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attac...Show more |
2Pivotal Pivotal Software2Apps Manager Pivotal Application ServiceJun 17, 2026 Oct 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more |