CWE-1236: CWE-1236

96
Total CVEs
24
Critical
58
High
8.1
Avg CVSS

Yearly Trend

2026
5
2025
25
2024
13
2023
24
2022
12

Top Affected Vendors

1 Ibm 8
2 Phpjabbers 7
3 Fortinet 2
4 Sesami 2
5 Nokia 1
6 Alf 1
7 Ncr 1
8 Exports And Reports Project 1
9 Automationanywhere 1
10 Puppet 1

All CWE-1236 CVEs (96)

CVE-2021-47901
9.8

Dirsearch 0.4.1 contains a CSV injection vulnerability that allows attackers to inject Excel formulas into generated CSV reports. When attackers contr...

Jan 27, 2026
CVE-2023-47295
9.8

CVE-2023-47295 is a CSV injection vulnerability in NCR Terminal Handler v1.5.1 that allows attackers to execute arbitrary commands by injecting malici...

Jun 23, 2025
CVE-2024-55532
9.8

This vulnerability allows CSV formula injection in Apache Ranger's export feature, enabling attackers to execute arbitrary commands or exfiltrate data...

Mar 3, 2025
CVE-2023-46400
9.8

KWHotel 0.47 contains a CSV formula injection vulnerability in the add guest function that allows attackers to inject malicious formulas into exported...

Jan 23, 2025
CVE-2024-47485
9.8

A CSV injection vulnerability in HikCentral Master Lite allows attackers to embed executable commands in CSV files. When users open these malicious fi...

Oct 18, 2024
CVE-2024-29375
9.8

A CSV injection vulnerability in Addactis IBNRS v.3.10.3.107 allows remote attackers to execute arbitrary code by uploading a malicious .ibnrs file co...

Apr 4, 2024
CVE-2023-51763
9.8

CVE-2023-51763 is a CSV injection vulnerability in ActiveAdmin's csv_builder.rb that allows attackers to inject malicious formulas into exported CSV f...

Dec 24, 2023
CVE-2022-46809
9.8

This CVE describes a CSV injection vulnerability in the ReviewX WordPress plugin for WooCommerce. Attackers can embed malicious formulas in CSV files ...

Nov 7, 2023
CVE-2022-45360
9.8

This vulnerability allows CSV injection attacks in the WordPress Commenter Emails plugin. Attackers can embed malicious formulas in CSV files that exe...

Nov 7, 2023
CVE-2022-45810
9.8

This CVE describes a CSV injection vulnerability in the Icegram Express WordPress plugin. Attackers can embed malicious formulas in CSV files that, wh...

Nov 7, 2023
CVE-2022-46803
9.8

This vulnerability allows unauthenticated attackers to inject malicious formulas into CSV files exported by the Noptin WordPress plugin. When victims ...

Nov 7, 2023
CVE-2022-46802
9.8

This vulnerability allows attackers to inject malicious formulas into CSV files processed by the WooCommerce plugin, which can lead to arbitrary code ...

Nov 7, 2023
CVE-2023-23796
9.8

This CSV injection vulnerability in the Form Builder WordPress plugin allows attackers to inject malicious formulas into exported CSV files. When open...

Nov 7, 2023
CVE-2020-10131
9.8

CVE-2020-10131 is a CSV macro injection vulnerability in SearchBlox's 'Featured Results' parameter that allows attackers to execute arbitrary commands...

Sep 6, 2023
CVE-2022-28481
9.8

The CSV-Safe gem versions before 3.0.0 fail to properly sanitize special characters in CSV output, allowing CSV injection attacks. This vulnerability ...

May 1, 2022
CVE-2022-0142
9.8

The Visual Form Builder WordPress plugin before version 3.0.8 is vulnerable to CSV injection, allowing low-privileged or unauthenticated users to inje...

Apr 12, 2022
CVE-2022-26249
9.8

Survey King v0.3.0 has a CSV injection vulnerability in Excel export functionality that allows attackers to execute arbitrary code or access sensitive...

Mar 24, 2022
CVE-2021-3188
9.8

CVE-2021-3188 is a CSV injection vulnerability in phpList 3.6.0 that allows attackers to inject malicious formulas into exported CSV files via the ema...

Jan 26, 2021
CVE-2020-22274
9.8

CVE-2020-22274 is a CSV injection vulnerability in JomSocial 4.7.6 that allows attackers to inject malicious formulas into exported CSV files. When vi...

Nov 4, 2020
CVE-2020-22276
9.8

CVE-2020-22276 is a CSV injection vulnerability in the WeForms WordPress plugin version 1.4.7 that allows attackers to inject malicious formulas into ...

Nov 4, 2020
CVE-2023-47534
9.6

This vulnerability allows attackers to execute arbitrary code or commands on Fortinet FortiClientEMS systems by exploiting improper neutralization of ...

Mar 12, 2024
CVE-2026-23873
9.0

CVE-2026-23873 is a CSV injection vulnerability in hustoj's contest rank export functionality that allows attackers to embed Excel formulas in nicknam...

Jan 22, 2026
CVE-2024-47572
9.0

This vulnerability allows attackers to execute arbitrary code on Fortinet FortiSOAR systems by manipulating CSV files. Attackers can craft malicious C...

Jan 14, 2025
CVE-2020-4627
9.0

CVE-2020-4627 is a CSV injection vulnerability in IBM Cloud Pak for Security 1.3.0.1 that allows remote attackers to execute arbitrary commands on aff...

Nov 30, 2020
CVE-2023-53929
8.8

CVE-2023-53929 is a CSV injection vulnerability in phpMyFAQ 3.1.12 that allows authenticated users to inject malicious formulas into their profile nam...

Dec 17, 2025
CVE-2023-53913
8.8

CVE-2023-53913 is a CSV injection vulnerability in Rukovoditel 3.3.1 that allows authenticated users to inject malicious formulas into user profile fi...

Dec 17, 2025
CVE-2023-51336
8.8

CVE-2023-51336 is a CSV injection vulnerability in PHPJabbers Meeting Room Booking System v1.0 that allows attackers to execute remote code by injecti...

Feb 20, 2025
CVE-2023-51333
8.8

PHPJabbers Cinema Booking System v1.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code on the server. This affects ad...

Feb 20, 2025
CVE-2023-51319
8.8

CVE-2023-51319 is a CSV injection vulnerability in PHPJabbers Bus Reservation System v1.1 that allows attackers to execute arbitrary code through mali...

Feb 20, 2025
CVE-2023-51311
8.8

CVE-2023-51311 is a CSV injection vulnerability in PHPJabbers Car Park Booking System v3.0 that allows attackers to execute remote code by exploiting ...

Feb 20, 2025
CVE-2023-51302
8.8

PHPJabbers Hotel Booking System v4.0 has a CSV injection vulnerability that allows attackers to execute arbitrary code when malicious CSV files are pr...

Feb 19, 2025
CVE-2024-53555
8.8

A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code by uploading specially crafted CSV files. This affects organi...

Nov 26, 2024
CVE-2023-48207
8.8

CVE-2023-48207 is a CSV injection vulnerability in Availability Booking Calendar 5.0 that allows attackers to inject malicious formulas into exported ...

Dec 7, 2023
CVE-2023-41798
8.8

This CVE describes a CSV injection vulnerability in the Directorist WordPress plugin. Attackers can embed malicious formulas in CSV files that execute...

Nov 7, 2023
CVE-2022-38702
8.8

This vulnerability allows authenticated WordPress users with export permissions to inject malicious formulas into CSV files exported via the WP CSV Ex...

Nov 7, 2023
CVE-2022-42882
8.8

This vulnerability allows authenticated attackers to inject malicious formulas into CSV files exported by the Simple CSV/XLS Exporter WordPress plugin...

Nov 7, 2023
CVE-2023-36527
8.8

This CVE describes a CSV injection vulnerability in the WordPress Post to CSV plugin by BestWebSoft. Attackers can embed malicious formulas in CSV fil...

Nov 7, 2023
CVE-2022-28864
8.8

CVE-2022-28864 is a CSV injection vulnerability in Nokia NetAct's Administration of Measurements website section. Malicious users can inject code into...

Jul 24, 2023
CVE-2023-33410
8.8

Minical 1.0.0 and earlier contains a CSV injection vulnerability in the Accounting module's Customer Name field that allows remote code execution when...

Jun 5, 2023
CVE-2023-2258
8.8

This vulnerability allows CSV formula injection attacks in alf.io event management software. Attackers can embed malicious formulas in CSV files that ...

Apr 24, 2023
CVE-2022-1539
8.8

The Exports and Reports WordPress plugin before version 0.9.2 contains a CSV injection vulnerability that allows attackers to inject malicious formula...

Jul 25, 2022
CVE-2022-2240
8.8

The Request a Quote WordPress plugin through version 2.3.7 allows unauthenticated attackers to upload malicious CSV files. When an administrator downl...

Jul 25, 2022
CVE-2021-39022
8.8

This vulnerability in IBM Guardium Data Encryption allows CSV injection attacks where malicious formulas can be embedded in exported CSV files. When o...

Mar 10, 2022
CVE-2021-41824
8.8

CVE-2021-41824 is a CSV injection vulnerability in Craft CMS that allows attackers to inject malicious formulas into exported CSV files. When victims ...

Sep 30, 2021
CVE-2021-27020
8.8

CVE-2021-27020 is a CSV injection vulnerability in Puppet Enterprise where user input wasn't properly sanitized during CSV export operations. This all...

Aug 30, 2021
CVE-2021-33256
8.8

A CSV injection vulnerability in ManageEngine ADSelfService Plus allows unauthenticated attackers to inject malicious formulas into the login panel. W...

Aug 9, 2021
CVE-2020-22390
8.8

CVE-2020-22390 is a CSV injection vulnerability in Akaunting accounting software that allows attackers to inject malicious formulas into exported CSV ...

Jun 21, 2021
CVE-2023-53905
8.0

ProjectSend r1605 contains a CSV injection vulnerability where authenticated users can embed malicious formulas in user profile names. When administra...

Dec 17, 2025
CVE-2024-45084
8.0

This vulnerability in IBM Cognos Controller allows authenticated attackers to perform formula injection attacks by manipulating file contents. Success...

Feb 19, 2025
CVE-2021-38963
8.0

This CSV injection vulnerability in IBM Aspera Console allows authenticated attackers to execute arbitrary code on affected systems by tricking users ...

Sep 25, 2024

About CWE-1236 (CWE-1236)

Our database tracks 96 CVEs classified as CWE-1236, with 24 rated critical and 58 rated high severity. The average CVSS score for CWE-1236 vulnerabilities is 8.1.

External reference: View CWE-1236 on MITRE CWE →

Monitor CWE-1236 Vulnerabilities

Get alerted when new CWE-1236 CVEs affect your infrastructure.

Start Monitoring Free