CWE-1236— Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.— MITRE CWE catalog
322 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1236page 1 of 7
- CVE-2026-31049CRITICALCVSS 9.8EG 9.82026-04-14
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
- CVE-2020-36962CRITICALCVSS 9.8EG 9.82026-01-28
Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the…
- CVE-2021-47901CRITICALCVSS 9.8EG 9.82026-01-27
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths contai…
- CVE-2020-36941CRITICALCVSS 9.8EG 9.82026-01-27
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas th…
- CVE-2025-56267CRITICALCVSS 9.8EG 9.82025-09-08
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.
- CVE-2023-47295CRITICALCVSS 9.8EG 9.82025-06-23
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.
- CVE-2024-55532CRITICALCVSS 9.8EG 9.82025-03-03
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
- CVE-2023-46401CRITICALCVSS 9.8EG 9.82025-01-23
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
- CVE-2023-46400CRITICALCVSS 9.8EG 9.82025-01-23
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
- CVE-2024-47485CRITICALCVSS 9.8EG 9.82024-10-18
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
- CVE-2024-29375CRITICALCVSS 9.8EG 9.82024-04-04
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve …
- CVE-2023-51763CRITICALCVSS 9.8EG 9.82023-12-24
csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.
- CVE-2020-10131CRITICALCVSS 9.8EG 9.82023-09-06
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
- CVE-2023-4006CRITICALCVSS 9.8EG 9.82023-07-31
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
- CVE-2022-3603CRITICALCVSS 9.8EG 9.82022-11-28
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.
- CVE-2022-3634CRITICALCVSS 9.8EG 9.82022-11-21
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection
- CVE-2022-3600CRITICALCVSS 9.8EG 9.82022-11-21
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
- CVE-2022-3574CRITICALCVSS 9.8EG 9.82022-11-14
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
- CVE-2022-3463CRITICALCVSS 9.8EG 9.82022-11-07
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
- CVE-2022-22425CRITICALCVSS 9.8EG 9.82022-11-03
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
- CVE-2022-3393CRITICALCVSS 9.8EG 9.82022-10-25
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
- CVE-2022-28481CRITICALCVSS 9.8EG 9.82022-05-01
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
- CVE-2022-0142CRITICALCVSS 9.8EG 9.82022-04-12
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- CVE-2022-26249CRITICALCVSS 9.8EG 9.82022-03-24
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
- CVE-2021-38180CRITICALCVSS 9.8EG 9.82021-10-12
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's com…
- CVE-2021-3188CRITICALCVSS 9.8EG 9.82021-01-26
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
- CVE-2020-22274CRITICALCVSS 9.8EG 9.82020-11-04
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
- CVE-2020-22276CRITICALCVSS 9.8EG 9.82020-11-04
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
- CVE-2020-11548CRITICALCVSS 9.8EG 9.82020-04-05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is p…
- CVE-2020-7947CRITICALCVSS 9.8EG 9.82020-04-01
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validat…
- CVE-2020-9347CRITICALCVSS 9.8EG 9.82020-03-16
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they…
- CVE-2019-0403CRITICALCVSS 9.8EG 9.82019-12-11
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.
- CVE-2019-4521CRITICALCVSS 9.8EG 9.82019-12-10
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.
- CVE-2019-16184CRITICALCVSS 9.8EG 9.82019-09-09
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
- CVE-2019-13144CRITICALCVSS 9.8EG 9.82019-07-05
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
- CVE-2019-12765CRITICALCVSS 9.8EG 9.82019-06-11
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
- CVE-2018-20752CRITICALCVSS 9.8EG 9.82019-02-04
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitiz…
- CVE-2018-11652CRITICALCVSS 9.8EG 9.82018-06-01
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
- CVE-2018-8092CRITICALCVSS 9.8EG 9.82018-04-18
Mautic before 2.13.0 allows CSV injection.
- CVE-2022-27858CRITICALCVSS 7.4EG 9.82022-11-08
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
- CVE-2022-46809CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a thr…
- CVE-2022-46803CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.
- CVE-2022-46801CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0.
- CVE-2022-45370CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.
- CVE-2022-46802CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8.
- CVE-2022-45357CRITICALCVSS 6.1EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application.This issue affects 1003 Mortgage Application: from n/a through 1.75.
- CVE-2022-45810CRITICALCVSS 4.7EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newslett…
- CVE-2022-45360CRITICALCVSS 4.7EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1.
- CVE-2023-23796CRITICALCVSS 4.7EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Contact Forms.This issue affects Form Builder | Create Responsive Contact Forms: from n/a through 1.9.9.0.
- CVE-2023-22719CRITICALCVSS 4.7EG 9.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
Map vulnerabilities like CWE-1236 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1236 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →