CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 5 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18900 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report. | ||
| CVE-2020-13146 | Hig | 0.57 | 8.8 | 0.01 | May 18, 2020 | Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature. | ||
| CVE-2019-17661 | Hig | 0.57 | 8.8 | 0.02 | Nov 8, 2019 | A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious… | ||
| CVE-2019-16184 | Cri | 0.57 | 9.8 | 0.02 | Sep 9, 2019 | A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file. | ||
| CVE-2019-16120 | Hig | 0.57 | 8.8 | 0.03 | Sep 8, 2019 | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. | ||
| CVE-2019-12961 | Hig | 0.57 | 8.8 | 0.01 | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function. | ||
| CVE-2018-20468 | Hig | 0.57 | 8.8 | 0.02 | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code… | ||
| CVE-2019-12134 | Hig | 0.57 | 8.8 | 0.01 | Jun 6, 2019 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export. | ||
| CVE-2019-11872 | Hig | 0.57 | 8.8 | 0.02 | May 29, 2019 | The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through… | ||
| CVE-2018-7201 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel. | ||
| CVE-2018-8092 | Cri | 0.57 | 9.8 | 0.02 | Apr 18, 2018 | Mautic before 2.13.0 allows CSV injection. | ||
| CVE-2018-7304 | Hig | 0.57 | 8.8 | 0.01 | Feb 21, 2018 | Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation. | ||
| CVE-2018-16308 | Hig | 0.56 | 8.6 | 0.02 | Sep 1, 2018 | The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | ||
| CVE-2018-15571 | Hig | 0.56 | 8.6 | 0.01 | Aug 28, 2018 | The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. | ||
| CVE-2023-0721 | Hig | 0.54 | 8.3 | 0.01 | Jun 9, 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are… | ||
| CVE-2020-9372 | Hig | 0.54 | 7.8 | 0.09 | Mar 4, 2020 | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The… | ||
| CVE-2018-11526 | Hig | 0.54 | 7.8 | 0.05 | Jun 19, 2018 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | ||
| CVE-2018-10504 | Hig | 0.54 | 7.8 | 0.05 | Apr 27, 2018 | The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | ||
| CVE-2023-53905 | Hig | 0.52 | 8.0 | 0.00 | Dec 17, 2025 | ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV… | ||
| CVE-2024-45084 | Hig | 0.52 | 8.0 | 0.00 | Feb 19, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents. |
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
- risk 0.57cvss 8.8epss 0.01
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
- risk 0.57cvss 8.8epss 0.02
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious…
- risk 0.57cvss 9.8epss 0.02
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
- risk 0.57cvss 8.8epss 0.03
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
- risk 0.57cvss 8.8epss 0.01
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code…
- risk 0.57cvss 8.8epss 0.01
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.
- risk 0.57cvss 8.8epss 0.02
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through…
- risk 0.57cvss 8.8epss 0.01
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
- risk 0.57cvss 9.8epss 0.02
Mautic before 2.13.0 allows CSV injection.
- risk 0.57cvss 8.8epss 0.01
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
- risk 0.56cvss 8.6epss 0.02
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
- risk 0.56cvss 8.6epss 0.01
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
- risk 0.54cvss 8.3epss 0.01
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are…
- risk 0.54cvss 7.8epss 0.09
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The…
- risk 0.54cvss 7.8epss 0.05
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
- risk 0.54cvss 7.8epss 0.05
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
- risk 0.52cvss 8.0epss 0.00
ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV…
- risk 0.52cvss 8.0epss 0.00
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.