VYPR

CWE-1236

Improper Neutralization of Formula Elements in a CSV File

BaseIncomplete

Description

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (305)

page 9 of 16
  • CVE-2018-16651HigSep 7, 2018
    risk 0.47cvss 7.2epss 0.01

    The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

  • CVE-2018-11525HigJun 19, 2018
    risk 0.47cvss 7.8epss 0.05

    The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

  • CVE-2018-9137MedApr 19, 2018
    risk 0.47cvss 6.8epss 0.03

    Open-AudIT before 2.2 has CSV Injection.

  • CVE-2025-52612HigJun 4, 2026
    risk 0.46cvss 7.1epss 0.00

    HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .

  • CVE-2025-58855HigSep 5, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin ap-honeypot allows Reflected XSS.This issue affects AP HoneyPot WordPress Plugin: from n/a through <= 1.4.

  • CVE-2024-25007HigApr 4, 2024
    risk 0.46cvss 7.1epss 0.00

    Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity…

  • CVE-2023-35899HigMar 21, 2024
    risk 0.46cvss 7.0epss 0.01

    IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper…

  • CVE-2023-22877HigAug 28, 2023
    risk 0.46cvss 7.0epss 0.01

    IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.

  • CVE-2023-28958HigJul 10, 2023
    risk 0.46cvss 7.0epss 0.01

    IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.

  • CVE-2026-45263higJul 14, 2026
    risk 0.45cvss epss

    ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A low-privilege user (`lowpriv`) created a customer with `nombre = "=SUM(1+1)*cmd|/c calc!A1"`. An admin then exported `ListCliente` to CSV via `?action=export&option=CSV`.…

  • CVE-2021-25962HigSep 29, 2021
    risk 0.45cvss 8.0epss 0.01

    “Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the…

  • CVE-2025-62417HigOct 16, 2025
    risk 0.44cvss 7.8epss 0.00

    Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as…

  • CVE-2023-3527MedJul 18, 2023
    risk 0.44cvss 6.8epss 0.01

    A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used…

  • CVE-2022-46408MedJun 29, 2023
    risk 0.44cvss 6.8epss 0.01

    Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected…

  • CVE-2023-3302HigJun 23, 2023
    risk 0.44cvss 7.8epss 0.00

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

  • CVE-2023-2629HigMay 10, 2023
    risk 0.44cvss 7.8epss 0.00

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.

  • CVE-2022-41791MedNov 17, 2022
    risk 0.44cvss 6.8epss 0.01

    Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.

  • CVE-2022-1544HigMay 1, 2022
    risk 0.44cvss 7.8epss 0.02

    Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of…

  • CVE-2021-43257HigApr 14, 2022
    risk 0.44cvss 7.8epss 0.01

    Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel.

  • CVE-2021-43515HigApr 8, 2022
    risk 0.44cvss 7.8epss 0.01

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.