CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

298 vulnerabilities with CWE-1236
CVE-2026-54243 MEDIUM
Statamic: CSV formula injection in form submission exports
CVSS 6.1
CVE-2026-14846 MEDIUM
Incorrect neutralisation in the PrestaShop firmware
CVE-2026-55452 HIGH
Snipe-IT: CSV formula injection in Activity Report export
CVSS 7.3
CVE-2026-50179 MEDIUM
Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
CVSS 4.2
CVE-2026-46672 MEDIUM
Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
CVSS 4.6
CVE-2026-47693 MEDIUM
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
CVSS 6.9
CVE-2026-5242 HIGH
Code Injection in Mia Technologies' Pizzy Library
CVSS 8.8
CVE-2026-10248 MEDIUM
SourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injection
CVSS 4.7
CVE-2026-9673 MEDIUM
json-2-csv < 5.5.11 - Improper Neutralization of Formula Elements in a CSV File
CVSS 6.8
CVE-2026-41073 MEDIUM
RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and similar apps
CVSS 4.6
CVE-2026-35157 MEDIUM
Dell ECS 3.8.1.0-3.8.1.7 and ObjectScale < 4.3.0.0 - Unauthenticated Remote Code Execution via CSV Formula Injection
CVSS 5.8
CVE-2026-42267 MEDIUM
Kimai: Formula Injection via tag names in XLSX export
CVSS 5.7
CVE-2026-27644 MEDIUM
traccar allows CSV formula injection via exported position data
CVSS 6.5
CVE-2026-31049 CRITICAL
Hostbill 2025-11-24/2025-12-01 - Privilege Escalation
CVSS 9.8
CVE-2026-39424 MEDIUM
MaxKB has CSV Injection in its Application Chat Export Functionality
CVSS 4.7
CVE-2026-24447 MEDIUM
Movable Type 8.0.2-8.0.8, 8.8.0-8.8.1, 9.0.4-9.0.5 - CSV Injection
CVSS 6.5
CVE-2026-23873 CRITICAL
hustoj < 26.01.31 - CSV Injection via Contest Rank Export Nickname Field
CVSS 9.0
CVE-2025-52612 HIGH
HCL iControl was affected by Export CSV - CSV Injection vulnerability.
CVSS 7.1
CVE-2025-67851 MEDIUM
moodle < 4.1.22 - Formula Injection via CSV Export
CVSS 6.1
CVE-2025-61873 LOW
Best Practical RT <4.4.9-6.0.2 - Code Injection
CVSS 2.6
CVE-2025-66834 HIGH
TrueConf Server <5.5.2.10813 - Formula Injection
CVSS 7.3
CVE-2025-14229 MEDIUM
SourceCodester Inventory Management System 1.0 - Code Injection
CVSS 4.7
CVE-2025-51735 HIGH
HCL Technologies Ltd. Unica 12.0.0. - Code Injection
CVSS 7.5
CVE-2025-13133 MEDIUM
Simple User Import Export <1.1.7 - Code Injection
CVSS 6.6
CVE-2025-12249 MEDIUM
Axosoft Scrum and Bug Tracking 22.1.1.11545 - Code Injection
CVSS 6.3
Details
Vulnerabilities 298