CWE-1236: CWE-1236

96
Total CVEs
24
Critical
58
High
8.1
Avg CVSS

Yearly Trend

2026
5
2025
25
2024
13
2023
24
2022
12

Top Affected Vendors

1 Ibm 8
2 Phpjabbers 7
3 Fortinet 2
4 Sesami 2
5 Nokia 1
6 Alf 1
7 Ncr 1
8 Exports And Reports Project 1
9 Automationanywhere 1
10 Puppet 1

All CWE-1236 CVEs (96)

CVE-2022-2027
8.0

This vulnerability allows CSV formula injection attacks in the titra time tracking software. Attackers can craft malicious CSV files that execute form...

Jun 9, 2022
CVE-2022-22121
8.0

CVE-2022-22121 is a CSV injection vulnerability in NocoDB that allows low-privileged attackers to inject malicious formulas into exported CSV files. W...

Jan 10, 2022
CVE-2020-36503
8.0

This vulnerability in the Connections Business Directory WordPress plugin allows CSV injection through unvalidated/sanitized fields. Attackers can inj...

Nov 1, 2021
CVE-2021-25962
8.0

CVE-2021-25962 is a formula injection vulnerability in the Shuup e-commerce platform that allows customers to inject malicious payloads into billing a...

Sep 29, 2021
CVE-2021-25960
8.0

This is a CSV injection vulnerability in SuiteCRM that allows low-privileged attackers to inject malicious formulas into input fields. When an adminis...

Sep 29, 2021
CVE-2021-24441
8.0

This CSV injection vulnerability in the Sign-up Sheets WordPress plugin allows attackers to embed malicious formulas in exported CSV files. When opene...

Jul 12, 2021
CVE-2025-62417
7.8

Bagisto eCommerce platform versions before 2.3.8 accept product data starting with spreadsheet formula characters (=, +, -, @). When exported to CSV a...

Oct 16, 2025
CVE-2024-41226
7.8

A CSV injection vulnerability in Automation Anywhere Automation 360 allows attackers to execute arbitrary code via crafted payloads in CSV files. This...

Aug 6, 2024
CVE-2022-3604
7.8

The Contact Form Entries WordPress plugin before version 1.3.0 does not properly validate user input when exporting data to CSV files, allowing attack...

Jan 16, 2024
CVE-2023-3302
7.8

This vulnerability allows CSV formula injection in Admidio, enabling attackers to execute arbitrary commands or exfiltrate data when users open malici...

Jun 23, 2023
CVE-2023-2629
7.8

This vulnerability allows CSV formula injection attacks in Pimcore Customer Data Framework. Attackers can embed malicious formulas in CSV files that e...

May 10, 2023
CVE-2022-1544
7.8

This CVE describes a CSV injection vulnerability in the yii-helpers library prior to version 1.2.1. Attackers can embed malicious formulas in CSV file...

May 1, 2022
CVE-2021-43515
7.8

CVE-2021-43515 is a CSV injection vulnerability in Kimai time tracking software that allows attackers to inject malicious formulas into exported CSV f...

Apr 8, 2022
CVE-2022-23868
7.8

RuoYi v4.7.2 contains a CSV injection vulnerability in the admin module that allows attackers to embed malicious formulas in exported Excel log files....

Mar 30, 2022
CVE-2021-46363
7.8

This vulnerability in Magnolia CMS allows attackers to inject malicious formulas into exported CSV/XLS files through the Export function. When victims...

Feb 11, 2022
CVE-2021-40848
7.8

This CVE describes a CSV injection vulnerability in Mahara e-portfolio software where exported CSV files could contain malicious formulas that spreads...

Nov 3, 2021
CVE-2020-25445
7.8

This CSV formula injection vulnerability in Booking Core 1.7.0 allows attackers to embed malicious Excel formulas in subscription data. When administr...

Jul 14, 2021
CVE-2021-29667
7.8

This CVE describes a CSV injection vulnerability in IBM Spectrum Scale that allows remote attackers to execute arbitrary commands on affected systems....

Apr 27, 2021
CVE-2024-22063
7.6

ZTE ZENIC ONE R58 products contain a command injection vulnerability that allows authenticated attackers to execute arbitrary commands. This enables m...

Dec 30, 2024
CVE-2025-51735
7.5

This CSV formula injection vulnerability in HCL Unica 12.0.0 allows attackers to execute arbitrary formulas when CSV files are opened in spreadsheet a...

Nov 28, 2025
CVE-2023-31295
7.5

A CSV injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 allows remote attackers to extract sensitive informati...

Dec 29, 2023
CVE-2023-31294
7.5

A CSV injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 allows remote attackers to extract sensitive informati...

Dec 29, 2023
CVE-2023-5527
7.4

This CSV injection vulnerability in the Business Directory Plugin for WordPress allows authenticated attackers with author-level permissions or higher...

Jun 18, 2024
CVE-2025-66834
7.3

A CSV formula injection vulnerability in TrueConf Server v5.5.2.10813 allows authenticated users to embed malicious spreadsheet formulas in exported c...

Dec 30, 2025
CVE-2021-22771
7.3

This vulnerability allows attackers to execute arbitrary commands on Schneider Electric Easergy T300 devices by exploiting improper CSV formula elemen...

Jul 21, 2021
CVE-2021-22153
7.3

This CVE allows remote code execution through BlackBerry UEM's Management Console spreadsheet application. An attacker could execute arbitrary command...

May 13, 2021
CVE-2022-45078
7.2

This CSV injection vulnerability in the User Blocker WordPress plugin allows authenticated attackers to inject malicious formulas into CSV files. When...

Nov 7, 2023
CVE-2023-23678
7.2

This vulnerability allows CSV injection attacks in the WP Cookie Consent WordPress plugin. Attackers can embed malicious formulas in CSV exports that ...

Nov 7, 2023
CVE-2023-31867
7.2

Sage X3 version 12.14.0.50-0 is vulnerable to CSV injection, which allows attackers to embed malicious formulas in exported CSV files. When users open...

Jun 22, 2023
CVE-2024-25007
7.1

Ericsson Network Manager (ENM) versions before 23.1 have a CSV injection vulnerability in the application log export function. Attackers with administ...

Apr 4, 2024
CVE-2023-35899
7.0

This CVE describes a CSV injection vulnerability in IBM Cloud Pak for Automation that allows remote attackers to execute arbitrary commands on affecte...

Mar 21, 2024
CVE-2023-28958
7.0

IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is vulnerable to CSV injection, allowing remote attackers to execute arbitrary commands on the ...

Jul 10, 2023
CVE-2025-13133
6.6

The Simple User Import Export WordPress plugin contains a CSV injection vulnerability that allows authenticated administrators to embed malicious form...

Nov 18, 2025
CVE-2026-24447
6.5

This vulnerability in Movable Type allows CSV injection attacks where malformed data input to the product results in malicious code being embedded in ...

Feb 4, 2026
CVE-2025-60852
6.5

A CSV injection vulnerability in Instant Developer Foundation allows attackers to embed malicious formulas in CSV exports. When users open these files...

Oct 23, 2025
CVE-2024-28764
6.5

CVE-2024-28764 is a CSV injection vulnerability in IBM WebSphere Automation 1.7.0 that allows attackers with network access to execute arbitrary comma...

May 1, 2024
CVE-2025-67851
6.1

A formula injection vulnerability in Moodle allows remote attackers to embed malicious formulas in exported data. When users export this data and open...

Feb 3, 2026
CVE-2025-8767
4.8

The AnWP Football Leagues WordPress plugin contains a CSV injection vulnerability that allows authenticated administrators to embed malicious formulas...

Aug 12, 2025
CVE-2025-39245
4.7

A CSV injection vulnerability in HikCentral Master Lite allows attackers to inject executable commands via malicious CSV data. This affects users who ...

Aug 29, 2025
CVE-2023-51298
4.7

PHPJabbers Event Booking Calendar v4.0 has a CSV injection vulnerability that allows attackers to inject malicious formulas into exported CSV files. W...

Feb 19, 2025
CVE-2023-5424
4.7

The WS Form LITE WordPress plugin versions up to 1.9.217 contain a CSV injection vulnerability that allows unauthenticated attackers to embed maliciou...

Jun 7, 2024
CVE-2025-11576
4.3

This CSV injection vulnerability in the AI Chatbot Free Models WordPress plugin allows unauthenticated attackers to embed malicious formulas in export...

Oct 24, 2025
CVE-2025-11254
4.3

This CSV injection vulnerability in the Contest Gallery WordPress plugin allows unauthenticated attackers to embed malicious formulas in exported CSV ...

Oct 11, 2025
CVE-2025-35033
4.1

Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows authenticated attackers to embed malicious macros in d...

Sep 29, 2025
CVE-2025-6838
4.1

The Broken Link Notifier WordPress plugin contains a CSV injection vulnerability that allows authenticated attackers with Contributor-level access or ...

Jul 11, 2025
CVE-2025-61873
2.6

This CSV injection vulnerability in Best Practical Request Tracker (RT) allows attackers to inject malicious formulas into exported TSV files. When us...

Jan 16, 2026

About CWE-1236 (CWE-1236)

Our database tracks 96 CVEs classified as CWE-1236, with 24 rated critical and 58 rated high severity. The average CVSS score for CWE-1236 vulnerabilities is 8.1.

External reference: View CWE-1236 on MITRE CWE →

Monitor CWE-1236 Vulnerabilities

Get alerted when new CWE-1236 CVEs affect your infrastructure.

Start Monitoring Free