CWE-1236: CWE-1236
Yearly Trend
Top Affected Vendors
All CWE-1236 CVEs (96)
Dirsearch 0.4.1 contains a CSV injection vulnerability that allows attackers to inject Excel formulas into generated CSV reports. When attackers contr...
Jan 27, 2026CVE-2023-47295 is a CSV injection vulnerability in NCR Terminal Handler v1.5.1 that allows attackers to execute arbitrary commands by injecting malici...
Jun 23, 2025This vulnerability allows CSV formula injection in Apache Ranger's export feature, enabling attackers to execute arbitrary commands or exfiltrate data...
Mar 3, 2025KWHotel 0.47 contains a CSV formula injection vulnerability in the add guest function that allows attackers to inject malicious formulas into exported...
Jan 23, 2025A CSV injection vulnerability in HikCentral Master Lite allows attackers to embed executable commands in CSV files. When users open these malicious fi...
Oct 18, 2024A CSV injection vulnerability in Addactis IBNRS v.3.10.3.107 allows remote attackers to execute arbitrary code by uploading a malicious .ibnrs file co...
Apr 4, 2024CVE-2023-51763 is a CSV injection vulnerability in ActiveAdmin's csv_builder.rb that allows attackers to inject malicious formulas into exported CSV f...
Dec 24, 2023This CVE describes a CSV injection vulnerability in the ReviewX WordPress plugin for WooCommerce. Attackers can embed malicious formulas in CSV files ...
Nov 7, 2023This vulnerability allows CSV injection attacks in the WordPress Commenter Emails plugin. Attackers can embed malicious formulas in CSV files that exe...
Nov 7, 2023This CVE describes a CSV injection vulnerability in the Icegram Express WordPress plugin. Attackers can embed malicious formulas in CSV files that, wh...
Nov 7, 2023This vulnerability allows unauthenticated attackers to inject malicious formulas into CSV files exported by the Noptin WordPress plugin. When victims ...
Nov 7, 2023This vulnerability allows attackers to inject malicious formulas into CSV files processed by the WooCommerce plugin, which can lead to arbitrary code ...
Nov 7, 2023This CSV injection vulnerability in the Form Builder WordPress plugin allows attackers to inject malicious formulas into exported CSV files. When open...
Nov 7, 2023CVE-2020-10131 is a CSV macro injection vulnerability in SearchBlox's 'Featured Results' parameter that allows attackers to execute arbitrary commands...
Sep 6, 2023The CSV-Safe gem versions before 3.0.0 fail to properly sanitize special characters in CSV output, allowing CSV injection attacks. This vulnerability ...
May 1, 2022The Visual Form Builder WordPress plugin before version 3.0.8 is vulnerable to CSV injection, allowing low-privileged or unauthenticated users to inje...
Apr 12, 2022Survey King v0.3.0 has a CSV injection vulnerability in Excel export functionality that allows attackers to execute arbitrary code or access sensitive...
Mar 24, 2022CVE-2021-3188 is a CSV injection vulnerability in phpList 3.6.0 that allows attackers to inject malicious formulas into exported CSV files via the ema...
Jan 26, 2021CVE-2020-22274 is a CSV injection vulnerability in JomSocial 4.7.6 that allows attackers to inject malicious formulas into exported CSV files. When vi...
Nov 4, 2020CVE-2020-22276 is a CSV injection vulnerability in the WeForms WordPress plugin version 1.4.7 that allows attackers to inject malicious formulas into ...
Nov 4, 2020This vulnerability allows attackers to execute arbitrary code or commands on Fortinet FortiClientEMS systems by exploiting improper neutralization of ...
Mar 12, 2024CVE-2026-23873 is a CSV injection vulnerability in hustoj's contest rank export functionality that allows attackers to embed Excel formulas in nicknam...
Jan 22, 2026This vulnerability allows attackers to execute arbitrary code on Fortinet FortiSOAR systems by manipulating CSV files. Attackers can craft malicious C...
Jan 14, 2025CVE-2020-4627 is a CSV injection vulnerability in IBM Cloud Pak for Security 1.3.0.1 that allows remote attackers to execute arbitrary commands on aff...
Nov 30, 2020CVE-2023-53929 is a CSV injection vulnerability in phpMyFAQ 3.1.12 that allows authenticated users to inject malicious formulas into their profile nam...
Dec 17, 2025CVE-2023-53913 is a CSV injection vulnerability in Rukovoditel 3.3.1 that allows authenticated users to inject malicious formulas into user profile fi...
Dec 17, 2025CVE-2023-51336 is a CSV injection vulnerability in PHPJabbers Meeting Room Booking System v1.0 that allows attackers to execute remote code by injecti...
Feb 20, 2025PHPJabbers Cinema Booking System v1.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code on the server. This affects ad...
Feb 20, 2025CVE-2023-51319 is a CSV injection vulnerability in PHPJabbers Bus Reservation System v1.1 that allows attackers to execute arbitrary code through mali...
Feb 20, 2025CVE-2023-51311 is a CSV injection vulnerability in PHPJabbers Car Park Booking System v3.0 that allows attackers to execute remote code by exploiting ...
Feb 20, 2025PHPJabbers Hotel Booking System v4.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code when malicious CSV files are pr...
Feb 19, 2025A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code by uploading specially crafted CSV files. This affects organi...
Nov 26, 2024CVE-2023-48207 is a CSV injection vulnerability in Availability Booking Calendar 5.0 that allows attackers to inject malicious formulas into exported ...
Dec 7, 2023This CVE describes a CSV injection vulnerability in the Directorist WordPress plugin. Attackers can embed malicious formulas in CSV files that execute...
Nov 7, 2023This vulnerability allows authenticated WordPress users with export permissions to inject malicious formulas into CSV files exported via the WP CSV Ex...
Nov 7, 2023This vulnerability allows authenticated attackers to inject malicious formulas into CSV files exported by the Simple CSV/XLS Exporter WordPress plugin...
Nov 7, 2023This CVE describes a CSV injection vulnerability in the WordPress Post to CSV plugin by BestWebSoft. Attackers can embed malicious formulas in CSV fil...
Nov 7, 2023CVE-2022-28864 is a CSV injection vulnerability in Nokia NetAct's Administration of Measurements website section. Malicious users can inject code into...
Jul 24, 2023Minical 1.0.0 and earlier contains a CSV injection vulnerability in the Accounting module's Customer Name field that allows remote code execution when...
Jun 5, 2023This vulnerability allows CSV formula injection attacks in alf.io event management software. Attackers can embed malicious formulas in CSV files that ...
Apr 24, 2023The Exports and Reports WordPress plugin before version 0.9.2 contains a CSV injection vulnerability that allows attackers to inject malicious formula...
Jul 25, 2022The Request a Quote WordPress plugin through version 2.3.7 allows unauthenticated attackers to upload malicious CSV files. When an administrator downl...
Jul 25, 2022This vulnerability in IBM Guardium Data Encryption allows CSV injection attacks where malicious formulas can be embedded in exported CSV files. When o...
Mar 10, 2022CVE-2021-41824 is a CSV injection vulnerability in Craft CMS that allows attackers to inject malicious formulas into exported CSV files. When victims ...
Sep 30, 2021CVE-2021-27020 is a CSV injection vulnerability in Puppet Enterprise where user input wasn't properly sanitized during CSV export operations. This all...
Aug 30, 2021A CSV injection vulnerability in ManageEngine ADSelfService Plus allows unauthenticated attackers to inject malicious formulas into the login panel. W...
Aug 9, 2021CVE-2020-22390 is a CSV injection vulnerability in Akaunting accounting software that allows attackers to inject malicious formulas into exported CSV ...
Jun 21, 2021ProjectSend r1605 contains a CSV injection vulnerability where authenticated users can embed malicious formulas in user profile names. When administra...
Dec 17, 2025This vulnerability in IBM Cognos Controller allows authenticated attackers to perform formula injection attacks by manipulating file contents. Success...
Feb 19, 2025This CSV injection vulnerability in IBM Aspera Console allows authenticated attackers to execute arbitrary code on affected systems by tricking users ...
Sep 25, 2024About CWE-1236 (CWE-1236)
Our database tracks 96 CVEs classified as CWE-1236, with 24 rated critical and 58 rated high severity. The average CVSS score for CWE-1236 vulnerabilities is 8.1.
External reference: View CWE-1236 on MITRE CWE →
Monitor CWE-1236 Vulnerabilities
Get alerted when new CWE-1236 CVEs affect your infrastructure.
Start Monitoring Free