CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (305)
page 8 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11819 | Hig | 0.51 | 7.8 | 0.01 | May 8, 2019 | Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name. | ||
| CVE-2018-16275 | Hig | 0.51 | 7.8 | 0.01 | Aug 31, 2018 | OPSWAT MetaDefender before v4.11.2 allows CSV injection. | ||
| CVE-2025-55745 | Hig | 0.50 | 8.8 | 0.01 | Aug 22, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious… | ||
| CVE-2022-2112 | Hig | 0.50 | 8.8 | 0.01 | Jun 17, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. | ||
| CVE-2022-24770 | Hig | 0.50 | 8.8 | 0.01 | Mar 17, 2022 | `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output… | ||
| CVE-2021-41824 | Hig | 0.50 | 8.8 | 0.01 | Sep 30, 2021 | Craft CMS before 3.7.14 allows CSV injection. | ||
| CVE-2025-51735 | Hig | 0.49 | 7.5 | 0.00 | Nov 28, 2025 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. | ||
| CVE-2024-22063 | Hig | 0.49 | 7.6 | 0.01 | Dec 30, 2024 | The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices. | ||
| CVE-2024-3232 | Hig | 0.49 | 7.6 | 0.00 | Jul 16, 2024 | A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232 | ||
| CVE-2023-31295 | Hig | 0.49 | 7.5 | 0.01 | Dec 29, 2023 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. | ||
| CVE-2023-31294 | Hig | 0.49 | 7.5 | 0.01 | Dec 29, 2023 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. | ||
| CVE-2022-41616 | Hig | 0.49 | 7.6 | 0.01 | Nov 7, 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1. | ||
| CVE-2022-27858 | Hig | 0.48 | 7.4 | 0.01 | Nov 8, 2022 | CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress. | ||
| CVE-2021-22771 | Hig | 0.48 | 7.3 | 0.01 | Jul 21, 2021 | A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution. | ||
| CVE-2021-22153 | Hig | 0.48 | 7.3 | 0.01 | May 13, 2021 | A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine… | ||
| CVE-2020-7049 | Hig | 0.48 | 7.3 | 0.01 | Jun 30, 2020 | Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. | ||
| CVE-2020-13247 | Hig | 0.48 | 7.3 | 0.01 | Jun 24, 2020 | BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area. | ||
| CVE-2025-66834 | Hig | 0.47 | 7.3 | 0.00 | Dec 30, 2025 | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name. | ||
| CVE-2023-37219 | Hig | 0.47 | 7.3 | 0.00 | Jul 30, 2023 | Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File | ||
| CVE-2023-31867 | Hig | 0.47 | 7.2 | 0.01 | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. |
- risk 0.51cvss 7.8epss 0.01
Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.
- risk 0.51cvss 7.8epss 0.01
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
- risk 0.50cvss 8.8epss 0.01
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious…
- risk 0.50cvss 8.8epss 0.01
Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.
- risk 0.50cvss 8.8epss 0.01
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output…
- risk 0.50cvss 8.8epss 0.01
Craft CMS before 3.7.14 allows CSV injection.
- risk 0.49cvss 7.5epss 0.00
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
- risk 0.49cvss 7.6epss 0.01
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.
- risk 0.49cvss 7.6epss 0.00
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
- risk 0.49cvss 7.5epss 0.01
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
- risk 0.49cvss 7.5epss 0.01
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
- risk 0.49cvss 7.6epss 0.01
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya Export Users Data CSV.This issue affects Export Users Data CSV: from n/a through 2.1.
- risk 0.48cvss 7.4epss 0.01
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
- risk 0.48cvss 7.3epss 0.01
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
- risk 0.48cvss 7.3epss 0.01
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine…
- risk 0.48cvss 7.3epss 0.01
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
- risk 0.48cvss 7.3epss 0.01
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
- risk 0.47cvss 7.3epss 0.00
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
- risk 0.47cvss 7.3epss 0.00
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
- risk 0.47cvss 7.2epss 0.01
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.