VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 8 of 16
  • CVE-2019-11819HigMay 8, 2019
    risk 0.51cvss 7.8epss 0.01

    Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.

  • CVE-2018-16275HigAug 31, 2018
    risk 0.51cvss 7.8epss 0.01

    OPSWAT MetaDefender before v4.11.2 allows CSV injection.

  • CVE-2025-55745HigAug 22, 2025
    risk 0.50cvss 8.8epss 0.01

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious…

  • CVE-2022-2112HigJun 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

  • CVE-2022-24770HigMar 17, 2022
    risk 0.50cvss 8.8epss 0.01

    `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output…

  • CVE-2021-41824HigSep 30, 2021
    risk 0.50cvss 8.8epss 0.01

    Craft CMS before 3.7.14 allows CSV injection.

  • CVE-2025-51735HigNov 28, 2025
    risk 0.49cvss 7.5epss 0.00

    CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-22063HigDec 30, 2024
    risk 0.49cvss 7.6epss 0.01

    The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.

  • CVE-2024-3232HigJul 16, 2024
    risk 0.49cvss 7.6epss 0.00

    A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232

  • CVE-2023-31295HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.01

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.

  • CVE-2023-31294HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.01

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.

  • CVE-2022-41616HigNov 7, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.

  • CVE-2022-27858HigNov 8, 2022
    risk 0.48cvss 7.4epss 0.01

    CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.

  • CVE-2021-22771HigJul 21, 2021
    risk 0.48cvss 7.3epss 0.01

    A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.

  • CVE-2021-22153HigMay 13, 2021
    risk 0.48cvss 7.3epss 0.01

    A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine…

  • CVE-2020-7049HigJun 30, 2020
    risk 0.48cvss 7.3epss 0.01

    Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.

  • CVE-2020-13247HigJun 24, 2020
    risk 0.48cvss 7.3epss 0.01

    BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.

  • CVE-2025-66834HigDec 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

  • CVE-2023-37219HigJul 30, 2023
    risk 0.47cvss 7.3epss 0.00

    Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

  • CVE-2023-31867HigJun 22, 2023
    risk 0.47cvss 7.2epss 0.01

    Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.