CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 1 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12765 | Cri | 0.68 | 9.8 | 0.10 | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. | ||
| CVE-2018-9035 | Cri | 0.66 | 9.6 | 0.07 | Apr 4, 2018 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form. | ||
| CVE-2026-31049 | Cri | 0.64 | 9.8 | 0.01 | Apr 14, 2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field | ||
| CVE-2021-47901 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the… | ||
| CVE-2020-36941 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened… | ||
| CVE-2025-56267 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2025 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | ||
| CVE-2023-47295 | Cri | 0.64 | 9.8 | 0.01 | Jun 23, 2025 | A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings. | ||
| CVE-2023-46401 | Cri | 0.64 | 9.8 | 0.00 | Jan 23, 2025 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. | ||
| CVE-2023-46400 | Cri | 0.64 | 9.8 | 0.00 | Jan 23, 2025 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. | ||
| CVE-2024-47485 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2024 | There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file. | ||
| CVE-2024-29375 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2024 | CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters. | ||
| CVE-2020-10131 | Cri | 0.64 | 9.8 | 0.02 | Sep 6, 2023 | SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter. | ||
| CVE-2022-3574 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2022 | The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. | ||
| CVE-2022-3463 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2022 | The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection | ||
| CVE-2022-22425 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598." | ||
| CVE-2022-3393 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2022 | The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection | ||
| CVE-2022-0142 | Cri | 0.64 | 9.8 | 0.03 | Apr 12, 2022 | The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | ||
| CVE-2022-26249 | Cri | 0.64 | 9.8 | 0.02 | Mar 24, 2022 | Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack. | ||
| CVE-2021-38180 | Cri | 0.64 | 9.8 | 0.02 | Oct 12, 2021 | SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to… | ||
| CVE-2021-33256 | Hig | 0.64 | 8.8 | 0.79 | Aug 9, 2021 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User… |
- risk 0.68cvss 9.8epss 0.10
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
- risk 0.66cvss 9.6epss 0.07
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
- risk 0.64cvss 9.8epss 0.01
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
- risk 0.64cvss 9.8epss 0.00
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the…
- risk 0.64cvss 9.8epss 0.00
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened…
- risk 0.64cvss 9.8epss 0.01
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.
- risk 0.64cvss 9.8epss 0.01
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.
- risk 0.64cvss 9.8epss 0.00
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
- risk 0.64cvss 9.8epss 0.00
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
- risk 0.64cvss 9.8epss 0.01
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
- risk 0.64cvss 9.8epss 0.01
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.
- risk 0.64cvss 9.8epss 0.02
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
- risk 0.64cvss 9.8epss 0.01
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
- risk 0.64cvss 9.8epss 0.01
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
- risk 0.64cvss 9.8epss 0.01
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
- risk 0.64cvss 9.8epss 0.01
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
- risk 0.64cvss 9.8epss 0.03
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
- risk 0.64cvss 9.8epss 0.02
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
- risk 0.64cvss 9.8epss 0.02
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to…
- risk 0.64cvss 8.8epss 0.79
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…