VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (317)

page 8 of 16
  • CVE-2020-25170HigNov 6, 2020
    risk 0.51cvss 7.8epss 0.01

    An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.

  • CVE-2020-26507HigNov 5, 2020
    risk 0.51cvss 7.8epss 0.01

    A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other computers. By providing formula code in the “Notes” functionality in the main screen, an attacker can…

  • CVE-2020-24707HigOct 28, 2020
    risk 0.51cvss 7.8epss 0.01

    Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.

  • CVE-2020-4302HigOct 12, 2020
    risk 0.51cvss 7.8epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-crafted excel file, an attacker could exploit this vulnerability to execute arbitrary code on the…

  • CVE-2019-20002HigApr 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.

  • CVE-2019-20184HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.02

    KeePass 2.4.1 allows CSV injection in the title field of a CSV export.

  • CVE-2019-15092HigAug 23, 2019
    risk 0.51cvss 7.3epss 0.05

    The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

  • CVE-2019-14352HigJul 28, 2019
    risk 0.51cvss 7.8epss 0.01

    In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is…

  • CVE-2019-11819HigMay 8, 2019
    risk 0.51cvss 7.8epss 0.01

    Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.

  • CVE-2018-16275HigAug 31, 2018
    risk 0.51cvss 7.8epss 0.01

    OPSWAT MetaDefender before v4.11.2 allows CSV injection.

  • CVE-2025-55745HigAug 22, 2025
    risk 0.50cvss 8.8epss 0.01

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious…

  • CVE-2022-2112HigJun 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

  • CVE-2022-24770HigMar 17, 2022
    risk 0.50cvss 8.8epss 0.01

    `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output…

  • CVE-2021-41824HigSep 30, 2021
    risk 0.50cvss 8.8epss 0.01

    Craft CMS before 3.7.14 allows CSV injection.

  • CVE-2025-51735HigNov 28, 2025
    risk 0.49cvss 7.5epss 0.00

    CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2024-22063HigDec 30, 2024
    risk 0.49cvss 7.6epss 0.01

    The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.

  • CVE-2024-3232HigJul 16, 2024
    risk 0.49cvss 7.6epss 0.00

    A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232

  • CVE-2023-31295HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.01

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.

  • CVE-2023-31294HigDec 29, 2023
    risk 0.49cvss 7.5epss 0.01

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.

  • CVE-2022-41616HigNov 7, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.