The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Volume of CVEs assigned to CWE-1236 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
298 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33256HIGH A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username paramete | Aug 9, 2021 | 8.8 | 70 | NO | NO |
CVE-2018-11652CRITICAL CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly in | Jun 1, 2018 | 9.8 | 57 | NO | YES |
CVE-2019-12765CRITICAL An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. | Jun 11, 2019 | 9.8 | 48 | NO | YES |
CVE-2019-14749HIGH An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are gene | Aug 7, 2019 | 8.8 | 46 | NO | YES |
CVE-2018-9035CRITICAL CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas i | Apr 4, 2018 | 9.6 | 42 | NO | YES |
CVE-2018-10258HIGH A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV | May 1, 2018 | 8.8 | 40 | NO | YES |
CVE-2018-10255HIGH A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exp | May 1, 2018 | 8.8 | 40 | NO | YES |
CVE-2018-9107HIGH CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandle | Mar 28, 2018 | 8.8 | 40 | NO | YES |
CVE-2018-10257HIGH A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exporte | May 1, 2018 | 8.8 | 39 | NO | YES |
CVE-2018-9106HIGH CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in | Mar 28, 2018 | 8.8 | 39 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.