VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 15 of 16
  • CVE-2026-41073MedMay 22, 2026
    risk 0.23cvss 4.6epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output…

  • CVE-2025-11576MedOct 24, 2025
    risk 0.21cvss 4.3epss 0.00

    The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This…

  • CVE-2025-11254MedOct 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into…

  • CVE-2026-50179MedJul 7, 2026
    risk 0.19cvss 4.2epss 0.00

    Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no…

  • CVE-2025-7061LowJul 4, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2024-53921LowDec 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

  • CVE-2025-61873LowJan 16, 2026
    risk 0.17cvss 2.6epss 0.00

    Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

  • CVE-2025-1421LowMay 21, 2025
    risk 0.16cvss epss 0.00

    Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access…

  • CVE-2018-11652CriJun 1, 2018
    risk 0.05cvss 9.8epss 0.24

    CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

  • CVE-2020-15255HigOct 16, 2020
    risk 0.03cvss 8.7epss 0.04

    In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version…

  • CVE-2026-65875HigAug 3, 2026
    risk 0.00cvss 7.1epss 0.00

    BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

  • CVE-2026-54243MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value…

  • CVE-2026-14846MedJul 13, 2026
    risk 0.00cvss epss 0.00

    In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that…

  • CVE-2026-55452HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged…

  • CVE-2024-53260MedNov 27, 2024
    risk 0.00cvss 6.8epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated…

  • CVE-2023-48709HigApr 15, 2024
    risk 0.00cvss 8.0epss 0.01

    iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users…

  • CVE-2024-28111MedMar 6, 2024
    risk 0.00cvss 6.5epss 0.01

    Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who…

  • CVE-2023-3493HigJun 30, 2023
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-2258HigApr 24, 2023
    risk 0.00cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

  • CVE-2022-2027HigJun 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.