Skip to main content

CWE archive

CWE-1236 CVEs

Programmatic archive

298 CVEs tagged with CWE-123638 Critical, 137 High, 111 Medium, 12 Low, 0 Unrated.

CVE-2026-54243

Published Jul 17, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutrali…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-14846

Published Jul 13, 2026

In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Updat…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55452

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes t…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-50179

Published Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-co…

CVSS 4.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46672

Published Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format c…

CVSS 4.6 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-47693

Published Jun 23, 2026

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export func…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-5242

Published Jun 15, 2026

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-52612

Published Jun 4, 2026

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanit…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10248

Published Jun 1, 2026

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of t…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-9673

Published May 28, 2026

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject f…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
25.9

CVE-2026-41073

Published May 22, 2026

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerabili…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-35157

Published May 11, 2026

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in th…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42267

Published May 8, 2026

Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27644

Published May 5, 2026

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and compu…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-54348

Published May 5, 2026

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas into vendor name fields that execute on the workstation of…

CVSS 8.7 · High

CVE-2026-31049

Published Apr 14, 2026

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
31.0

CVE-2026-39424

Published Apr 14, 2026

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable to Improper Neutralization of Formula Elements in a CSV Fil…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-24447

Published Feb 4, 2026

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-67851

Published Feb 3, 2026

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing ma…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36962

Published Jan 28, 2026

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can su…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47901

Published Jan 27, 2026

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft…

CVSS 5.1 · Medium

CVE-2020-36941

Published Jan 27, 2026

Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-23873

Published Jan 22, 2026

hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the con…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-61873

Published Jan 16, 2026

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

CVSS 2.6 · Low

CVE-2025-66834

Published Dec 30, 2025

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Nam…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 298 CVEsPage 1 of 12