CWE-1236— Improper Neutralization of Formula Elements in a CSV File
241 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1236page 3 of 5
- CVE-2021-25962HIGHCVSS 8.0EG 8.02021-09-29
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator …
- CVE-2021-27020HIGHCVSS 8.8EG 8.82021-08-30
Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
- CVE-2021-27839MEDIUMCVSS 4.4EG 4.42021-03-03
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions such as redirecting admins to unknown or harmful websites, or disclosing other clients' details that …
- CVE-2021-29667HIGHCVSS 7.8EG 7.82021-04-27
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Forc…
- CVE-2021-3188CRITICALCVSS 9.8EG 9.82021-01-26
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
- CVE-2021-33256HIGHCVSS 8.8EG 8.82021-08-09
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtai…
- CVE-2021-36334MEDIUMCVSS 5.9EG 6.82021-11-23
Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged attacker, may potentially exploit this vulnerability, leading to arbitrary code execution on end user machine
- CVE-2021-37131MEDIUMCVSS 6.8EG 6.82021-10-27
There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input valida…
- CVE-2021-37702HIGHCVSS 8.0EG 8.02021-08-18
Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a worka…
- CVE-2021-38180CRITICALCVSS 9.8EG 9.82021-10-12
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's com…
- CVE-2021-38424MEDIUMCVSS 5.9EG 5.92021-11-03
The tag interface of Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to an attacker injecting formulas into the tag data. Those formulas may then be executed when it is opened with a spreadsheet application.
- CVE-2021-38963HIGHCVSS 8.0EG 8.02024-09-25
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could…
- CVE-2021-39022HIGHCVSS 8.8EG 8.82022-03-10
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command w…
- CVE-2021-40848HIGHCVSS 7.8EG 7.82021-11-03
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.
- CVE-2021-41270MEDIUMCVSS 6.5EG 6.52021-11-24
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3…
- CVE-2021-41824HIGHCVSS 8.8EG 8.82021-09-30
Craft CMS before 3.7.14 allows CSV injection.
- CVE-2021-43257HIGHCVSS 7.8EG 7.82022-04-14
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.
- CVE-2021-43515HIGHCVSS 7.8EG 7.82022-04-08
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
- CVE-2021-46363HIGHCVSS 7.8EG 7.82022-02-11
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exp…
- CVE-2022-0142CRITICALCVSS 9.8EG 9.82022-04-12
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- CVE-2022-1194HIGHCVSS 8.8EG 8.82022-09-16
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
- CVE-2022-1202HIGHCVSS 7.8EG 7.82022-06-13
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
- CVE-2022-1539HIGHCVSS 8.8EG 8.82022-07-25
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously i…
- CVE-2022-1544HIGHCVSS 7.8EG 7.82022-05-01
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, cod…
- CVE-2022-2027HIGHCVSS 8.0EG 8.02022-06-09
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
- CVE-2022-2112HIGHCVSS 8.8EG 8.82022-06-17
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
- CVE-2022-22121HIGHCVSS 8.0EG 8.02022-01-10
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Manag…
- CVE-2022-2240HIGHCVSS 8.8EG 8.82022-07-25
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
- CVE-2022-22425CRITICALCVSS 9.8EG 9.82022-11-03
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
- CVE-2022-2268HIGHCVSS 7.2EG 7.22022-07-04
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary fi…
- CVE-2022-22689HIGHCVSS 8.8EG 8.82022-02-04
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrar…
- CVE-2022-23868HIGHCVSS 7.8EG 7.82022-03-30
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
- CVE-2022-2429MEDIUMCVSS 6.5EG 8.02022-09-06
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as …
- CVE-2022-24770HIGHCVSS 8.8EG 8.82022-03-17
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging …
- CVE-2022-26249CRITICALCVSS 9.8EG 9.82022-03-24
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
- CVE-2022-26867MEDIUMCVSS 5.9EG 8.02022-06-02
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpr…
- CVE-2022-27858HIGHCVSS 7.4EG 9.82022-11-08
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
- CVE-2022-2798HIGHCVSS 8.0EG 8.02022-09-16
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data
- CVE-2022-28481CRITICALCVSS 9.8EG 9.82022-05-01
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
- CVE-2022-28864HIGHCVSS 8.8EG 8.82023-07-24
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .x…
- CVE-2022-29315HIGHCVSS 8.8EG 8.82022-04-19
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
- CVE-2022-3026MEDIUMCVSS 6.5EG 8.82022-09-06
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrus…
- CVE-2022-3393CRITICALCVSS 9.8EG 9.82022-10-25
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
- CVE-2022-3463CRITICALCVSS 9.8EG 9.82022-11-07
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
- CVE-2022-35281MEDIUMCVSS 5.5EG 8.82023-01-09
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.
- CVE-2022-3558HIGHCVSS 8.0EG 8.02022-11-07
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
- CVE-2022-3574CRITICALCVSS 9.8EG 9.82022-11-14
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
- CVE-2022-3600CRITICALCVSS 9.8EG 9.82022-11-21
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
- CVE-2022-3603CRITICALCVSS 9.8EG 9.82022-11-28
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.
- CVE-2022-3604HIGHCVSS 7.8EG 7.82024-01-16
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
Map vulnerabilities like CWE-1236 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1236 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →