Skip to main content

CWE archive

CWE-1236 CVEs

Programmatic archive

300 CVEs tagged with CWE-123638 Critical, 137 High, 113 Medium, 12 Low, 0 Unrated.

CVE-2020-4759

Published Nov 9, 2020

IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper valida…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25170

Published Nov 6, 2020

An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Exce…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26507

Published Nov 5, 2020

A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other comput…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25398

Published Nov 5, 2020

CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22274

Published Nov 4, 2020

JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-22278

Published Nov 4, 2020

phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15255

Published Oct 16, 2020

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4689

Published Oct 12, 2020

IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4302

Published Oct 12, 2020

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection. By persuading a victim to open a specially-cra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14026

Published Sep 22, 2020

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16214

Published Sep 11, 2020

In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutral…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-13826

Published Aug 20, 2020

A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10780

Published Aug 11, 2020

Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens th…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13247

Published Jun 24, 2020

BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13146

Published May 18, 2020

Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Rep…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20002

Published Apr 27, 2020

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11548

Published Apr 5, 2020

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV inj…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7947

Published Apr 1, 2020

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19676

Published Mar 18, 2020

A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Str…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9347

Published Mar 16, 2020

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 226-250 of 300 CVEsPage 10 of 12