VulnSea

CWE-1236

CVEs classified under CWE-1236, newest first.

24 CVEsRSS

CVE-2026-89246Medium· 5.4PoC
1w ago

WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated…

TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-86745Medium· 6.5
1w ago

Snipe-IT is an IT asset management application

Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch …

Sunlitsnipeitapp · snipe-itEPSS 0.45%via NVD
CVE-2026-79971Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Sanitization of Custom Special Characters vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Sanitization of Custom Special Characters vulnerability. An unauthenticated attacker with remote access c…

Sunlitdell · secure_connect_gatewayEPSS 0.22%via NVD
CVE-2026-86742Medium· 6.5
1w ago

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, un…

Sunlitsnipeitapp · snipe-itEPSS 0.28%via NVD
CVE-2026-86257Medium· 5.4PoC⚖ disputed
2w ago

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…

Twilightwger-project · wgerEPSS 0.17%via NVD
CVE-2026-9852High· 7.8
2w ago

A CSV injection vulnerability exists in SYS600

A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute …

Twilighthitachienergy · microscada_x_sys600EPSS 0.19%via NVD
CVE-2026-76797Medium· 6.3
3w ago

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas

The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the clust…

Sunlitmongodb · mongosql_transition_readiness_toolEPSS 0.25%via NVD
CVE-2026-78209High· 8.2
4w ago

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a s…

TwilightEPSS 0.29%via NVD
CVE-2026-19501High· 8.8PoC
1mo ago

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…

CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…

MidnightEPSS 0.47%via NVD
CVE-2026-64955Medium· 6.1
1mo ago

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when exporting to CSV from various places su…

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to sanitize such cells when exporting to CSV from various places su…

SunlitEPSS 0.22%via NVD
CVE-2026-47705Critical· 9.6
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spr…

MidnightEPSS 0.48%via NVD
CVE-2026-18738Medium· 4.7
1mo ago

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, o…

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, o…

Sunlitshlinkio · ShlinkEPSS 0.38%via NVD
CVE-2026-65875High· 7.1
1mo ago

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

TwilightEPSS 0.15%via NVD
CVE-2026-45263High· 8.0
2mo ago

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

Twilightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-55452None
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escap…

SunlitEPSS 0.23%via NVD
CVE-2026-54243Medium· 6.1
2mo ago

Statamic Vulnerable to CSV formula injection in form submission exports

Statamic Vulnerable to CSV formula injection in form submission exports

Sunlitstatamic · statamic/cmsEPSS 0.34%via GHSA
CVE-2026-46672Medium· 4.6
3mo ago

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

Sunlitactual-app · @actual-app/cliEPSS 0.19%via GHSA
CVE-2026-50179Medium· 4.2
3mo ago

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

Sunlitactual-app · @actual-app/webEPSS 0.29%via GHSA
CVE-2026-47693Medium· 6.9
3mo ago

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Sunlitpoweradmin · poweradmin/poweradminEPSS 0.38%via GHSA
CVE-2026-9673Medium· 6.8
3mo ago

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are o…

SunlitEPSS 0.17%via NVD
CVE-2026-41073Medium· 4.6
4mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not san…

SunlitEPSS 0.17%via NVD
CVE-2025-66834High· 7.3
8mo ago

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

Twilighttrueconf · trueconf_serverEPSS 0.30%via NVD
CVE-2020-28861Medium· 5.3
5y ago

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by th…

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by th…

Sunlitopenasset · digital_asset_managementEPSS 2.3%via NVD
CVE-2019-14749High· 8.8PoC
7y ago

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user inp…

Midnightenhancesoft · osticketEPSS 7.7%via NVD
CWE-1236 vulnerabilities (CVEs) · VulnSea