VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (317)

page 10 of 16
  • CVE-2025-62417HigOct 16, 2025
    risk 0.44cvss 7.8epss 0.00

    Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as…

  • CVE-2023-3527MedJul 18, 2023
    risk 0.44cvss 6.8epss 0.01

    A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used…

  • CVE-2022-46408MedJun 29, 2023
    risk 0.44cvss 6.8epss 0.01

    Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected…

  • CVE-2023-3302HigJun 23, 2023
    risk 0.44cvss 7.8epss 0.00

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

  • CVE-2023-2629HigMay 10, 2023
    risk 0.44cvss 7.8epss 0.00

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.

  • CVE-2022-41791MedNov 17, 2022
    risk 0.44cvss 6.8epss 0.01

    Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.

  • CVE-2022-1544HigMay 1, 2022
    risk 0.44cvss 7.8epss 0.02

    Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of…

  • CVE-2021-43257HigApr 14, 2022
    risk 0.44cvss 7.8epss 0.01

    Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.

  • CVE-2021-43515HigApr 8, 2022
    risk 0.44cvss 7.8epss 0.01

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

  • CVE-2021-37131MedOct 27, 2021
    risk 0.44cvss 6.8epss 0.01

    There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker…

  • CVE-2021-21302MedFeb 26, 2021
    risk 0.44cvss 6.8epss 0.02

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2

  • CVE-2020-4689MedOct 12, 2020
    risk 0.44cvss 6.8epss 0.02

    IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.

  • CVE-2019-20180MedJan 9, 2020
    risk 0.44cvss 6.8epss 0.02

    The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

  • CVE-2025-13133MedNov 18, 2025
    risk 0.43cvss 6.6epss 0.00

    The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.1.7 via the 'Import/export users' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to embed untrusted…

  • CVE-2022-37905MedDec 12, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

  • CVE-2019-13181MedDec 16, 2019
    risk 0.43cvss 6.5epss 0.03

    A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

  • CVE-2026-24447MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7…

  • CVE-2025-60852MedOct 23, 2025
    risk 0.42cvss 6.5epss 0.00

    A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code…

  • CVE-2025-54752MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.

  • CVE-2024-28764MedMay 1, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.