CWE-1236
Improper Neutralization of Formula Elements in a CSV File
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
292 vulnerabilities with CWE-1236
CVE-2022-38061
MEDIUM
WordPress Export Post Info <1.2.0 - CSV Injection
CVSS 6.2
CVE-2022-38844
HIGH
EspoCRM 7.1.8 - Authenticated CSV Injection via Contact Creation
CVSS 8.0
CVE-2022-2798
HIGH
WordPress Affiliate Mgr <2.9.14 - Code Injection
CVSS 8.0
CVE-2022-1194
HIGH
Mobile Events Manager <1.4.8 - Code Injection
CVSS 8.8
CVE-2022-3026
MEDIUM
WP Users Exporter <1.4.2 - Code Injection
CVSS 6.5
CVE-2022-2429
MEDIUM
Ultimate SMS Notifications for WooCommerce <1.4.1 - Code Injection
CVSS 6.5
CVE-2022-2240
HIGH
Request a Quote WP <2.3.7 - Code Injection
CVSS 8.8
CVE-2022-1539
HIGH
Exports and Reports WP <0.9.2 - Code Injection
CVSS 8.8
CVE-2022-2112
HIGH
inventree/inventree <0.7.2 - Info Disclosure
CVSS 8.8
CVE-2022-1202
HIGH
WP-CRM < 1.2.1 - CSV Injection via Unsanitized Export Fields
CVSS 7.8
CVE-2022-2027
HIGH
kromitgmbh/titra <0.77.0 - Info Disclosure
CVSS 8.0
CVE-2022-26867
MEDIUM
PowerStore SW v2.1.1.0 - Code Injection
CVSS 5.9
CVE-2022-28481
CRITICAL
CSV-Safe gem < 3.0.0 - Code Injection
CVSS 9.8
CVE-2022-1544
HIGH
luya/yii-helpers < 1.2.1 - CSV Injection via Improper Neutralization of Formula Elements
CVSS 7.8
CVE-2022-29315
HIGH
Invicti Acunetix <14 - Code Injection
CVSS 8.8
CVE-2022-0142
CRITICAL
Visual Form Builder <3.0.8 - Code Injection
CVSS 9.8
CVE-2022-23868
HIGH
RuoYi v4.7.2 - CSV Injection via Log File Export
CVSS 7.8
CVE-2022-26249
CRITICAL
Survey King v0.3.0 - Code Injection
CVSS 9.8
CVE-2022-24770
HIGH
gradio < 2.8.11 - CSV Injection via Flagging Functionality
CVSS 8.8
CVE-2022-22689
HIGH
CA Harvest Software Change Manager <14.0.2 - RCE
CVSS 8.8
CVE-2022-22121
HIGH
NocoDB 0.81.0-0.83.8 - CSV Injection via User Management Export
CVSS 8.0
CVE-2021-47901
CRITICAL
dirsearch 0.4.1 - CSV Injection via Redirect Endpoint Path
CVSS 9.8
CVE-2021-38963
HIGH
IBM Aspera Console 3.4.0-3.4.4 - Command Injection
CVSS 8.0
CVE-2021-23286
MEDIUM
Eaton IPM Infrastructure <1.5.0plus205 - Code Injection
CVSS 5.7
CVE-2021-43257
HIGH
MantisBT < 2.25.3 - CSV Injection via CSV Export API
CVSS 7.8
Details
Vulnerabilities
292