CWE-1236— Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.— MITRE CWE catalog
322 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1236page 2 of 7
- CVE-2026-47705CRITICALCVSS 9.6EG 9.62026-08-11
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject sprea…
- CVE-2023-47534CRITICALCVSS 9.6EG 9.62024-03-12
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized…
- CVE-2019-19676CRITICALCVSS 9.6EG 9.62020-03-18
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can crea…
- CVE-2018-15474CRITICALCVSS 9.6EG 9.62018-09-07
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is…
- CVE-2018-9035CRITICALCVSS 9.6EG 9.62018-04-04
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
- CVE-2026-23873CRITICALCVSS 9.0EG 9.02026-01-22
hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export functionality (contestrank.xls.php and admi…
- CVE-2024-47572CRITICALCVSS 9.0EG 9.02025-01-14
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
- CVE-2020-4627CRITICALCVSS 9.0EG 9.02020-11-30
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
- CVE-2021-33256CRITICALCVSS 8.8EG 9.02021-08-09
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtai…
- CVE-2018-1774HIGHCVSS 8.9EG 8.92018-11-09
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 14869…
- CVE-2026-19501HIGHCVSS 8.8EG 8.82026-08-18
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spre…
- CVE-2026-5242HIGHCVSS 8.8EG 8.82026-06-15
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
- CVE-2025-52612HIGHCVSS 8.8EG 8.82026-06-04
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
- CVE-2023-54348HIGHCVSS 8.8EG 8.82026-05-05
ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of users who open the exported CSV in a spreadsheet applicatio…
- CVE-2023-53929HIGHCVSS 8.8EG 8.82025-12-17
phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code exec…
- CVE-2023-53913HIGHCVSS 8.8EG 8.82025-12-17
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports cu…
- CVE-2025-55745HIGHCVSS 8.8EG 8.82025-08-22
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability…
- CVE-2025-50572HIGHCVSS 8.8EG 8.82025-07-31
Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accep…
- CVE-2023-51336HIGHCVSS 8.8EG 8.82025-02-20
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any paramet…
- CVE-2023-51333HIGHCVSS 8.8EG 8.82025-02-20
PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters fi…
- CVE-2023-51319HIGHCVSS 8.8EG 8.82025-02-20
PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters f…
- CVE-2023-51311HIGHCVSS 8.8EG 8.82025-02-20
PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters …
- CVE-2023-51302HIGHCVSS 8.8EG 8.82025-02-19
PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters fie…
- CVE-2024-53555HIGHCVSS 8.8EG 8.82024-11-26
A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.
- CVE-2023-48207HIGHCVSS 8.8EG 8.82023-12-07
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
- CVE-2023-42004HIGHCVSS 8.8EG 8.82023-11-28
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
- CVE-2023-41798HIGHCVSS 8.8EG 8.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Cl…
- CVE-2023-25983HIGHCVSS 8.8EG 8.82023-11-07
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.
- CVE-2022-28864HIGHCVSS 8.8EG 8.82023-07-24
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .x…
- CVE-2023-33410HIGHCVSS 8.8EG 8.82023-06-05
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is use…
- CVE-2023-2258HIGHCVSS 8.8EG 8.82023-04-24
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
- CVE-2022-37905HIGHCVSS 8.8EG 8.82022-12-12
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underl…
- CVE-2022-40294HIGHCVSS 8.8EG 8.82022-10-31
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
- CVE-2022-1194HIGHCVSS 8.8EG 8.82022-09-16
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
- CVE-2022-2240HIGHCVSS 8.8EG 8.82022-07-25
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
- CVE-2022-1539HIGHCVSS 8.8EG 8.82022-07-25
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously i…
- CVE-2022-2112HIGHCVSS 8.8EG 8.82022-06-17
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
- CVE-2022-29315HIGHCVSS 8.8EG 8.82022-04-19
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
- CVE-2022-24770HIGHCVSS 8.8EG 8.82022-03-17
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging …
- CVE-2021-39022HIGHCVSS 8.8EG 8.82022-03-10
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command w…
- CVE-2022-22689HIGHCVSS 8.8EG 8.82022-02-04
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrar…
- CVE-2021-41824HIGHCVSS 8.8EG 8.82021-09-30
Craft CMS before 3.7.14 allows CSV injection.
- CVE-2021-27020HIGHCVSS 8.8EG 8.82021-08-30
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
- CVE-2020-22390HIGHCVSS 8.8EG 8.82021-06-21
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
- CVE-2020-4633HIGHCVSS 8.8EG 8.82020-12-11
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
- CVE-2020-25398HIGHCVSS 8.8EG 8.82020-11-05
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
- CVE-2020-22278HIGHCVSS 8.8EG 8.82020-11-04
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
- CVE-2020-22275HIGHCVSS 8.8EG 8.82020-11-04
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on th…
- CVE-2020-14026HIGHCVSS 8.8EG 8.82020-09-22
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
- CVE-2020-13826HIGHCVSS 8.8EG 8.82020-08-20
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
Map vulnerabilities like CWE-1236 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1236 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →