VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 10 of 16
  • CVE-2021-37131MedOct 27, 2021
    risk 0.44cvss 6.8epss 0.01

    There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker…

  • CVE-2020-4689MedOct 12, 2020
    risk 0.44cvss 6.8epss 0.02

    IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.

  • CVE-2019-20180MedJan 9, 2020
    risk 0.44cvss 6.8epss 0.02

    The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

  • CVE-2025-13133MedNov 18, 2025
    risk 0.43cvss 6.6epss 0.00

    The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted…

  • CVE-2022-37905MedDec 12, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

  • CVE-2019-13181MedDec 16, 2019
    risk 0.43cvss 6.5epss 0.03

    A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

  • CVE-2026-24447MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7…

  • CVE-2025-60852MedOct 23, 2025
    risk 0.42cvss 6.5epss 0.00

    A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code…

  • CVE-2025-54752MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.

  • CVE-2024-28764MedMay 1, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.

  • CVE-2023-47022MedFeb 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.

  • CVE-2022-3026MedSep 6, 2022
    risk 0.42cvss 6.5epss 0.01

    The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via the 'Export Users' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into profile information like…

  • CVE-2022-2429MedSep 6, 2022
    risk 0.42cvss 6.5epss 0.01

    The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input…

  • CVE-2021-1475MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see…

  • CVE-2021-1474MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see…

  • CVE-2019-16959MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.02

    SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

  • CVE-2019-6187MedNov 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being…

  • CVE-2025-12249MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing manipulation of the argument Title results in csv injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-9241MedAug 20, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

  • CVE-2023-5527HigJun 18, 2024
    risk 0.41cvss 7.4epss 0.00

    The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files…