VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 5 of 16
  • CVE-2017-18900CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

  • CVE-2020-13146HigMay 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.

  • CVE-2019-17661HigNov 8, 2019
    risk 0.57cvss 8.8epss 0.02

    A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious…

  • CVE-2019-16184CriSep 9, 2019
    risk 0.57cvss 9.8epss 0.02

    A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.

  • CVE-2019-16120HigSep 8, 2019
    risk 0.57cvss 8.8epss 0.03

    CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

  • CVE-2019-12961HigJun 25, 2019
    risk 0.57cvss 8.8epss 0.01

    LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.

  • CVE-2018-20468HigJun 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code…

  • CVE-2019-12134HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.01

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

  • CVE-2019-11872HigMay 29, 2019
    risk 0.57cvss 8.8epss 0.02

    The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through…

  • CVE-2018-7201HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

  • CVE-2018-8092CriApr 18, 2018
    risk 0.57cvss 9.8epss 0.02

    Mautic before 2.13.0 allows CSV injection.

  • CVE-2018-7304HigFeb 21, 2018
    risk 0.57cvss 8.8epss 0.01

    Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.

  • CVE-2018-16308HigSep 1, 2018
    risk 0.56cvss 8.6epss 0.02

    The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

  • CVE-2018-15571HigAug 28, 2018
    risk 0.56cvss 8.6epss 0.01

    The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.

  • CVE-2023-0721HigJun 9, 2023
    risk 0.54cvss 8.3epss 0.01

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and including, 3.3.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are…

  • CVE-2020-9372HigMar 4, 2020
    risk 0.54cvss 7.8epss 0.09

    The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The…

  • CVE-2018-11526HigJun 19, 2018
    risk 0.54cvss 7.8epss 0.05

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

  • CVE-2018-10504HigApr 27, 2018
    risk 0.54cvss 7.8epss 0.05

    The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.

  • CVE-2023-53905HigDec 17, 2025
    risk 0.52cvss 8.0epss 0.00

    ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV…

  • CVE-2024-45084HigFeb 19, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.