Total
300 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-44830 | 1 Event Registration Application Project | 1 Event Registration Application | 2025-04-29 | 7.8 High |
| Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file. | ||||
| CVE-2022-41675 | 1 Raidenmaild | 1 Raidenmaild | 2025-04-25 | 8 High |
| A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or disrupt service on the user side. | ||||
| CVE-2022-24770 | 1 Gradio Project | 1 Gradio | 2025-04-23 | 8.8 High |
| `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output data into a CSV file on the developer's computer. This can allow a user to save arbitrary text into the CSV file, such as commands. If a program like MS Excel opens such a file, then it automatically runs these commands, which could lead to arbitrary commands running on the user's computer. The problem has been patched as of `2.8.11`, which escapes the saved csv with single quotes. As a workaround, avoid opening csv files generated by `gradio` with Excel or similar spreadsheet programs. | ||||
| CVE-2023-51302 | 1 Phpjabbers | 1 Hotel Booking System | 2025-04-23 | 8.8 High |
| PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | ||||
| CVE-2023-51298 | 1 Phpjabbers | 1 Event Booking Calendar | 2025-04-22 | 4.7 Medium |
| PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | ||||
| CVE-2024-53260 | 1 Autolabproject | 1 Autolab | 2025-04-21 | 6.8 Medium |
| Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated as a formula. This could lead to leakage of information of students in the course roster by sending the data to a remote endpoint. This issue has been patched in the source code repository and the fix is expected to be released in the next version. Users are advised to manually patch their systems or to wait for the next release. There are no known workarounds for this vulnerability. | ||||
| CVE-2020-36531 | 1 Ibm | 1 Sevone Network Performance Management | 2025-04-15 | 6.3 Medium |
| A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely. | ||||
| CVE-2024-28764 | 2 Ibm, Linux | 3 Websphere Automation, Websphere Automation For Ibm Cloud Pak For Watson Aiops, Linux Kernel | 2025-04-11 | 6.5 Medium |
| IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. | ||||
| CVE-2022-37786 | 1 Wecube-platform Project | 1 Wecube-platform | 2025-04-11 | 6.3 Medium |
| An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page. | ||||
| CVE-2023-45597 | 1 Ailux | 1 Imx6 | 2025-04-10 | 5.9 Medium |
| A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2. | ||||
| CVE-2022-35281 | 1 Ibm | 2 Maximo Application Suite, Maximo Asset Management | 2025-04-09 | 5.5 Medium |
| IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335. | ||||
| CVE-2024-47485 | 1 Hikvision | 2 Hikcentral Master, Hikcentral Master Lite | 2025-03-13 | 9.8 Critical |
| There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file. | ||||
| CVE-2022-38061 | 1 Apasionados | 1 Export Post Info | 2025-02-20 | 6.2 Medium |
| Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress. | ||||
| CVE-2022-27858 | 1 Activity Log Project | 1 Activity Log | 2025-02-20 | 7.4 High |
| CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress. | ||||
| CVE-2023-46400 | 1 Kwhotel | 1 Kwhotel | 2025-02-07 | 4.3 Medium |
| KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. | ||||
| CVE-2019-16120 | 1 Liquidweb | 1 Event Tickets | 2025-02-07 | 8.8 High |
| CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. | ||||
| CVE-2023-29109 | 1 Sap | 4 Abap Platform, Application Interface Framework, Basis and 1 more | 2025-02-07 | 4.4 Medium |
| The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application. | ||||
| CVE-2023-48709 | 1 Combodo | 1 Itop | 2025-02-06 | 8 High |
| iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0. | ||||
| CVE-2023-46401 | 1 Kwhotel | 1 Kwhotel | 2025-02-04 | 8.8 High |
| KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. | ||||
| CVE-2023-2258 | 1 Alf | 1 Alf | 2025-02-04 | 8.8 High |
| Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. | ||||