CWE-1236
308 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Export Users To Csv Project 1Export Users To Csv Jun 17, 2026 Feb 28, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection. |
LiteCart through 2.2.1 allows CSV injection via a customer's profile. |
KeePass 2.4.1 allows CSV injection in the title field of a CSV export. |
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file...Show more |
1Solarwinds 1Serv U Ftp Server Jun 17, 2026 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. |
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection. |
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-...Show more |
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informationa...Show more |
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attac...Show more |
2Pivotal Pivotal Software2Apps Manager Pivotal Application ServiceJun 17, 2026 Oct 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more |
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file. |
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. |
1Lenovo 1Xclarity Administrator Jun 17, 2026 Sep 3, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that coul...Show more |
1Webtoffee 1Import Export Wordpress Users Jun 17, 2026 Aug 23, 2019 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by th...Show more |
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 7, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or un...Show more |
In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the ven...Show more |
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5. |
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function. |
1Ibm 10Control Desk Maximo Asset ManagementMaximo For Aviation+7 moreJun 17, 2026 Jun 19, 2019 N/A· v4 8.0 HIGH· v3 8.5 HIGH· v2 IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680. |