← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Weformspro
1Weforms
Jun 17, 2026
Nov 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
1Easyregistrationforms
1Easy Registration Forms
Jun 17, 2026
Nov 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, ther...Show more
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.Show less
1Getgophish
1Gophish
Jun 17, 2026
Oct 28, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
1Anuko
1Time Tracker
Jun 17, 2026
Oct 16, 2020
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value...Show more
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Oct 12, 2020
N/A· v4
6.8 MEDIUM· v3
8.5 HIGH· v2
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
1Ibm
1Cognos Analytics
Jun 17, 2026
Oct 12, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploi...Show more
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176610.Show less
1Ozeki
1Ozeki Ng Sms Gateway
Jun 17, 2026
Sep 22, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
1Philips
1Patient Information Center Ix
Jun 17, 2026
Sep 11, 2020
N/A· v4
5.0 MEDIUM· v3
5.8 MEDIUM· v2
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special e...Show more
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.Show less
1I Doit
1I Doit
Jun 17, 2026
Aug 20, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
1Redhat
1Cloudforms Management Engine
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.3 MEDIUM· v3
4.9 MEDIUM· v2
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering...Show more
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.Show less
1Nozominetworks
1Guardian
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.3 HIGH· v3
8.5 HIGH· v2
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
1Boolebox
1Boolebox
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.3 HIGH· v3
8.5 HIGH· v2
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
1Edx
1Open Edx Platform
Jun 17, 2026
May 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
1Solarwinds
1Webhelpdesk
Jun 17, 2026
Apr 27, 2020
N/A· v4
7.8 HIGH· v3
6.0 MEDIUM· v2
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=g...Show more
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.Show less
1Search Meter Project
1Search Meter
Jun 17, 2026
Apr 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=searc...Show more
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.Show less
1Auth0
1Login By Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, a...Show more
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.Show less
1Arxes Tolina
1Arxes Tolina
Jun 17, 2026
Mar 18, 2020
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, a...Show more
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.Show less
1Zohocorp
1Manageengine Password Manager Pro
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this...Show more
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own productsShow less
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
1Codepeople
1Appointment Booking Calendar
Jun 17, 2026
Mar 4, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab...Show more
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.Show less