← Back
CWE-1236

298 CVEs • Abstraction: Base

Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

JSON object

Loading...

CVEs (298)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dokuwiki
1Dokuwiki
Nov 21, 2024
Sep 7, 2018
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code...Show more
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki.Show less
1Phpmyfaq
1Phpmyfaq
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Sep 1, 2018
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
1Opswat
1Metadefender
Nov 21, 2024
Aug 31, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
1Export Users To Csv Project
1Export Users To Csv
Nov 21, 2024
Aug 28, 2018
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
1Webtoffee
1Wordpress Comments Import And Export
Nov 21, 2024
Jun 19, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
1Algolplus
1Advanced Order Export For Woocommerce
Nov 21, 2024
Jun 19, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
1Cirt.net
1Nikto
Nov 21, 2024
Jun 1, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
1Codeslab
1Shopy Point Of Sale
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution...Show more
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less
1Hrsale Project
1Hrsale
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code exe...Show more
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less
1Clustercoding
1Blog Master Pro
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code...Show more
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.Show less
1Web Dorado
1Form Maker
Nov 21, 2024
Apr 27, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
1Open Audit
1Open Audit
Jun 17, 2026
Apr 19, 2018
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
Open-AudIT before 2.2 has CSV Injection.
1Mautic
1Mautic
Jun 17, 2026
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mautic before 2.13.0 allows CSV injection.
1Contact Form 7 To Database Extension Project
1Contact Form 7 To Database Extension
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
1Acyba
1Acymailing
Jun 17, 2026
Mar 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
1Acyba
1Acysms
Jun 17, 2026
Mar 28, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.
1Tiki
1Tiki
Jun 17, 2026
Feb 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd...Show more
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.Show less