← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Export Users To Csv Project
1Export Users To Csv
Jun 17, 2026
Feb 28, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
1Litecart
1Litecart
Jun 17, 2026
Feb 25, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
1Keepass
1Keepass
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
1Tablepress
1Tablepress
Jun 17, 2026
Jan 9, 2020
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file...Show more
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.Show less
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
1Sap
1Enable Now
Jun 17, 2026
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
1Ibm
1Cloud Pak System
Jun 17, 2026
Dec 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-...Show more
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.Show less
1Lenovo
1Xclarity Controller
Jun 17, 2026
Nov 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informationa...Show more
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.Show less
1Admincolumns
1Admin Columns
Jun 17, 2026
Nov 8, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attac...Show more
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.Show less
2Pivotal
Pivotal Software
2Apps Manager
Pivotal Application Service
Jun 17, 2026
Oct 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.Show less
1Limesurvey
1Limesurvey
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
1Liquidweb
1Event Tickets
Jun 17, 2026
Sep 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Sep 3, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that coul...Show more
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.Show less
1Webtoffee
1Import Export Wordpress Users
Jun 17, 2026
Aug 23, 2019
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by th...Show more
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.Show less
1Uipath
1Orchestrator
Nov 21, 2024
Aug 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
2Enhancesoft
Osticket
2Osticket
Osticket
Jul 10, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or un...Show more
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.Show less
1Joget
1Worfklow
Jun 17, 2026
Jul 28, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the ven...Show more
In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applicationsShow less
1Mytinytodo
1Mytinytodo
Jun 17, 2026
Jul 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
1Livezilla
1Livezilla
Jun 17, 2026
Jun 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
1Ibm
10Control Desk
Maximo Asset ManagementMaximo For Aviation+7 more
Jun 17, 2026
Jun 19, 2019
N/A· v4
8.0 HIGH· v3
8.5 HIGH· v2
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.