VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 3 of 16
  • CVE-2026-23873CriJan 22, 2026
    risk 0.59cvss 9.0epss 0.01

    hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export functionality (contestrank.xls.php and admin/ranklist_export.php). The application…

  • CVE-2024-47572CriJan 14, 2025
    risk 0.59cvss 9.0epss 0.01

    An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file

  • CVE-2020-4627CriNov 30, 2020
    risk 0.59cvss 9.0epss 0.02

    IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.

  • CVE-2020-36962CriJan 28, 2026
    risk 0.58cvss 9.8epss 0.11

    Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary…

  • CVE-2019-4071HigMay 9, 2019
    risk 0.58cvss 8.8epss 0.04

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.

  • CVE-2018-1774HigNov 9, 2018
    risk 0.58cvss 8.9epss 0.01

    IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.

  • CVE-2026-5242HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

  • CVE-2023-54348HigMay 5, 2026
    risk 0.57cvss 8.8epss 0.00

    ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of users who open the exported CSV in a spreadsheet application. Attackers can add malicious formulas…

  • CVE-2023-53929HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.01

    phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code execution when an administrator exports user…

  • CVE-2023-53913HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.01

    Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

  • CVE-2025-50572HigJul 31, 2025
    risk 0.57cvss 8.8epss 0.00

    Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report…

  • CVE-2024-55532CriMar 3, 2025
    risk 0.57cvss 9.8epss 0.01

    Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.

  • CVE-2023-51336HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51333HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51319HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51311HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51302HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2024-53555HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

  • CVE-2023-51763CriDec 24, 2023
    risk 0.57cvss 9.8epss 0.01

    csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.

  • CVE-2023-48207HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.