CWE-1236
308 CVEs • Abstraction: Base
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Clustercoding 1Blog Master Pro Nov 21, 2024 May 1, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code...Show more |
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. |
Open-AudIT before 2.2 has CSV Injection. |
Mautic before 2.13.0 allows CSV injection. |
1Contact Form 7 To Database Extension Project 1Contact Form 7 To Database Extension Jun 17, 2026 Apr 4, 2018 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. |
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export. |
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export. |
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd...Show more |