CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Description
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (317)
page 9 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27858 | Hig | 0.48 | 7.4 | 0.01 | Nov 8, 2022 | CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress. | ||
| CVE-2021-22771 | Hig | 0.48 | 7.3 | 0.01 | Jul 21, 2021 | A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution. | ||
| CVE-2021-22153 | Hig | 0.48 | 7.3 | 0.01 | May 13, 2021 | A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine… | ||
| CVE-2020-7049 | Hig | 0.48 | 7.3 | 0.01 | Jun 30, 2020 | Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. | ||
| CVE-2020-13247 | Hig | 0.48 | 7.3 | 0.01 | Jun 24, 2020 | BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area. | ||
| CVE-2025-66834 | Hig | 0.47 | 7.3 | 0.00 | Dec 30, 2025 | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name. | ||
| CVE-2023-37219 | Hig | 0.47 | 7.3 | 0.00 | Jul 30, 2023 | Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File | ||
| CVE-2023-31867 | Hig | 0.47 | 7.2 | 0.01 | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. | ||
| CVE-2018-16651 | Hig | 0.47 | 7.2 | 0.01 | Sep 7, 2018 | The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports. | ||
| CVE-2018-11525 | Hig | 0.47 | 7.8 | 0.05 | Jun 19, 2018 | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | ||
| CVE-2018-9137 | Med | 0.47 | 6.8 | 0.03 | Apr 19, 2018 | Open-AudIT before 2.2 has CSV Injection. | ||
| CVE-2026-65875 | Hig | 0.46 | 7.1 | 0.00 | Aug 3, 2026 | BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. | ||
| CVE-2025-52612 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | ||
| CVE-2025-58855 | Hig | 0.46 | 7.1 | 0.00 | Sep 5, 2025 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin ap-honeypot allows Reflected XSS.This issue affects AP HoneyPot WordPress Plugin: from n/a through <= 1.4. | ||
| CVE-2024-25007 | Hig | 0.46 | 7.1 | 0.00 | Apr 4, 2024 | Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity… | ||
| CVE-2023-35899 | Hig | 0.46 | 7.0 | 0.01 | Mar 21, 2024 | IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper… | ||
| CVE-2023-22877 | Hig | 0.46 | 7.0 | 0.01 | Aug 28, 2023 | IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368. | ||
| CVE-2023-28958 | Hig | 0.46 | 7.0 | 0.01 | Jul 10, 2023 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782. | ||
| CVE-2026-45263 | hig | 0.45 | — | — | Jul 14, 2026 | ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A low-privilege user (`lowpriv`) created a customer with `nombre = "=SUM(1+1)*cmd|/c calc!A1"`. An admin then exported `ListCliente` to CSV via `?action=export&option=CSV`.… | ||
| CVE-2021-25962 | Hig | 0.45 | 8.0 | 0.01 | Sep 29, 2021 | “Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the… |
- risk 0.48cvss 7.4epss 0.01
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
- risk 0.48cvss 7.3epss 0.01
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
- risk 0.48cvss 7.3epss 0.01
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine…
- risk 0.48cvss 7.3epss 0.01
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
- risk 0.48cvss 7.3epss 0.01
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
- risk 0.47cvss 7.3epss 0.00
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
- risk 0.47cvss 7.3epss 0.00
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
- risk 0.47cvss 7.2epss 0.01
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
- risk 0.47cvss 7.2epss 0.01
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
- risk 0.47cvss 7.8epss 0.05
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
- risk 0.47cvss 6.8epss 0.03
Open-AudIT before 2.2 has CSV Injection.
- risk 0.46cvss 7.1epss 0.00
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.
- risk 0.46cvss 7.1epss 0.00
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Formula Elements in a CSV File vulnerability in Denis V (Artprima) AP HoneyPot WordPress Plugin ap-honeypot allows Reflected XSS.This issue affects AP HoneyPot WordPress Plugin: from n/a through <= 1.4.
- risk 0.46cvss 7.1epss 0.00
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity…
- risk 0.46cvss 7.0epss 0.01
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper…
- risk 0.46cvss 7.0epss 0.01
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.
- risk 0.46cvss 7.0epss 0.01
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
- risk 0.45cvss —epss —
## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A low-privilege user (`lowpriv`) created a customer with `nombre = "=SUM(1+1)*cmd|/c calc!A1"`. An admin then exported `ListCliente` to CSV via `?action=export&option=CSV`.…
- risk 0.45cvss 8.0epss 0.01
“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the…