VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (315)

page 16 of 16
  • CVE-2025-11254MedOct 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into…

  • CVE-2026-50179MedJul 7, 2026
    risk 0.19cvss 4.2epss 0.00

    Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no…

  • CVE-2025-7061LowJul 4, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2024-53921LowDec 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

  • CVE-2025-61873LowJan 16, 2026
    risk 0.17cvss 2.6epss 0.00

    Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

  • CVE-2025-1421LowMay 21, 2025
    risk 0.16cvss —epss 0.00

    Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access…

  • CVE-2026-54243MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value…

  • CVE-2026-14846MedJul 13, 2026
    risk 0.00cvss —epss 0.00

    In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that…

  • CVE-2024-53260MedNov 27, 2024
    risk 0.00cvss 6.8epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated…

  • CVE-2023-48709HigApr 15, 2024
    risk 0.00cvss 8.0epss 0.01

    iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users…

  • CVE-2024-28111MedMar 6, 2024
    risk 0.00cvss 6.5epss 0.01

    Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who…

  • CVE-2023-3493HigJun 30, 2023
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-2258HigApr 24, 2023
    risk 0.00cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

  • CVE-2022-2027HigJun 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

  • CVE-2022-22121HigJan 10, 2022
    risk 0.00cvss 8.0epss 0.01

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a…