CWE-1236
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
298 vulnerabilities with CWE-1236
CVE-2022-46821
MEDIUM
Jackmail & Sarbacane Emails & Newsletters with Jackmail <= 1.2.22 - CSV Injection
CVSS 5.8
CVE-2022-46809
MEDIUM
WPDeveloper ReviewX < 1.6.7 - CSV Injection
CVSS 6.1
CVE-2022-46804
MEDIUM
Narola Infotech Solutions LLP <1.3 - Info Disclosure
CVSS 5.8
CVE-2022-46803
MEDIUM
Noptin Newsletter <1.9.5 - Info Disclosure
CVSS 6.1
CVE-2022-46801
MEDIUM
Paul Ryley Site Reviews <6.2.0 - Info Disclosure
CVSS 6.1
CVE-2022-45810
MEDIUM
Icegram Express <5.5.2 - Info Disclosure
CVSS 4.7
CVE-2022-45370
MEDIUM
WebToffee WordPress Comments Import & Export <2.3.1 - Info Disclosure
CVSS 6.1
CVE-2022-45360
MEDIUM
Commenter Emails <2.6.1 - Info Disclosure
CVSS 4.7
CVE-2022-45348
MEDIUM
anmari amr <4.59.4 - Info Disclosure
CVSS 5.8
CVE-2022-45078
MEDIUM
Solwin Infotech User Blocker <1.5.5 - Info Disclosure
CVSS 5.9
CVE-2022-46802
MEDIUM
WebToffee Product Reviews Import Export <1.4.8 - Info Disclosure
CVSS 6.1
CVE-2022-45357
MEDIUM
Lenderd 1003 Mortgage Application - Info Disclosure
CVSS 6.1
CVE-2022-47442
MEDIUM
UsersWP <= 1.2.3.9 - CSV Injection
CVSS 5.8
CVE-2022-45350
MEDIUM
Simple History <3.3.1 - CSV Injection
CVSS 5.8
CVE-2022-28864
HIGH
Nokia NetAct 22 - CSV Injection via Administration of Measurements TemplateName Parameter
CVSS 8.8
CVE-2022-46408
MEDIUM
Ericsson Network Manager <22.1 - RCE
CVSS 6.8
CVE-2022-35281
MEDIUM
IBM Maximo Asset Management 7.6.1.1-7.6.1.3 and Maximo Manage 8.3-8.4 - CSV Injection
CVSS 5.5
CVE-2022-37786
MEDIUM
WeCube Platform <3.2.2 - Code Injection
CVSS 6.3
CVE-2022-37905
MEDIUM
ArubaOS 7xxx Controllers - Boot Sequence Remote Code Execution
CVSS 6.6
CVE-2022-4034
MEDIUM
Appointment Hour Booking Plugin <1.3.72 - Code Injection
CVSS 5.8
CVE-2022-41675
HIGH
raidenmaild < 4.7.4 - Authenticated CSV Injection via Form Content Export
CVSS 8.0
CVE-2022-44830
HIGH
Sourcecodester Event Registration App v1.0 - Code Injection
CVSS 7.8
CVE-2022-41791
MEDIUM
ProfileGrid <5.1.6 - Code Injection
CVSS 6.8
CVE-2022-3574
CRITICAL
WPForms Pro <1.7.7 - Code Injection
CVSS 9.8
CVE-2022-27858
HIGH
WordPress Activity Log <2.8.3 - Code Injection
CVSS 7.4
Details
Vulnerabilities
298