CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

283 vulnerabilities with CWE-1236
CVE-2025-8808 MEDIUM
xujeff tianti <2.3 - CSV Injection
CVSS 4.3
CVE-2025-50572 HIGH
Archer 6.11.00204.10014 - RCE
CVSS 8.8
CVE-2025-54752 MEDIUM
PowerCMS - Code Injection
CVSS 6.5
CVE-2025-6838 MEDIUM
Broken Link Notifier <1.3.0 - Code Injection
CVSS 4.1
CVE-2025-7061 LOW
Intelbras InControl <2.21.60.9 - CSV Injection
CVSS 2.7
CVE-2025-1421 LOW
Konsola Proget <2.17.5 - Info Disclosure
CVE-2025-4546 MEDIUM
1Panel-dev MaxKB <1.10.7 - CSV Injection
CVSS 4.7
CVE-2025-1836 MEDIUM
Incorta 2023.4.3 - Code Injection
CVSS 4.3
CVE-2024-55532 CRITICAL
Apache Ranger <2.6.0 - Info Disclosure
CVSS 9.8
CVE-2024-45084 HIGH
IBM Cognos Controller <11.0.2 - Command Injection
CVSS 8.0
CVE-2024-47572 CRITICAL
Fortinet FortiSOAR <7.4.1 - Code Injection
CVSS 9.0
CVE-2024-22063 HIGH
ZTE ZENIC ONE R58 - Command Injection
CVSS 7.6
CVE-2024-9102 MEDIUM
phpLDAPadmin <1.2.6.7 - CSV Formula Injection
CVE-2024-53921 LOW
Samsung Magician 8.1.0 - Path Traversal
CVSS 2.8
CVE-2024-53260 MEDIUM
Autolab - Info Disclosure
CVSS 6.8
CVE-2024-53555 HIGH
Taiga <6.8.1 - Code Injection
CVSS 8.8
CVE-2024-51094 HIGH
Snipe-IT <7.0.13 - Privilege Escalation
CVSS 8.0
CVE-2024-47485 CRITICAL
HikCentral Master Lite - Code Injection
CVSS 9.8
CVE-2024-27321 HIGH
Refuel Autolabel <0.0.8 - RCE
CVSS 7.8
CVE-2024-27320 HIGH
Refuel Autolabel <0.0.8 - RCE
CVSS 7.8
CVE-2024-41226 HIGH
Automation Anywhere Automation 360 <21094 - Code Injection
CVSS 7.8
CVE-2024-3232 HIGH
Tenable Identity Exposure - Code Injection
CVSS 7.6
CVE-2024-27785 MEDIUM
Fortinet FortiAIOps <2.0.0 - RCE
CVSS 5.4
CVE-2024-28764 MEDIUM
IBM WebSphere Automation 1.7.0 - Command Injection
CVSS 6.5
CVE-2024-3214 MEDIUM
Relevanssi - A Better Search <4.22.1 - Code Injection
CVSS 5.8
Details
Vulnerabilities 283