← Back
CWE-1236

308 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sahipro
1Sahi Pro
Nov 21, 2024
Jun 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script...Show more
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.Show less
1Joomla
1Joomla
Jun 17, 2026
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
1Workday
1Workday
Jun 17, 2026
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export...Show more
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.Show less
1Incsub
1Hustle
Jun 17, 2026
May 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execut...Show more
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.Show less
1Projectsend
1Projectsend
Jun 17, 2026
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
1Ibm
2Spectrum Control
Tivoli Storage Productivity Center
Jun 17, 2026
May 9, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file con...Show more
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.Show less
1Alkacon
1Opencms
Jun 17, 2026
May 8, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.
1Symantec
1Endpoint Protection
Nov 21, 2024
Apr 25, 2019
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or web...Show more
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.Show less
1Recon Ng Project
1Recon Ng
Nov 21, 2024
Feb 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not...Show more
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can result in remote code execution for the attacker.Show less
1Ibm
1Api Connect
Nov 21, 2024
Nov 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IB...Show more
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.Show less
1Dokuwiki
1Dokuwiki
Nov 21, 2024
Sep 7, 2018
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code...Show more
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.Show less
1Phpmyfaq
1Phpmyfaq
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Sep 1, 2018
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
1Opswat
1Metadefender
Nov 21, 2024
Aug 31, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
1Export Users To Csv Project
1Export Users To Csv
Nov 21, 2024
Aug 28, 2018
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
1Webtoffee
1Wordpress Comments Import And Export
Nov 21, 2024
Jun 19, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
1Algolplus
1Advanced Order Export For Woocommerce
Nov 21, 2024
Jun 19, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
1Cirt.net
1Nikto
Nov 21, 2024
Jun 1, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
1Codeslab
1Shopy Point Of Sale
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution...Show more
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less
1Hrsale Project
1Hrsale
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code exe...Show more
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less