Skip to main content

CWE archive

CWE-1236 CVEs

Programmatic archive

298 CVEs tagged with CWE-123638 Critical, 137 High, 111 Medium, 12 Low, 0 Unrated.

CVE-2024-27320

Published Sep 12, 2024

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41226

Published Aug 6, 2024

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere dispu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3232

Published Jul 16, 2024

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form field…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27785

Published Jul 9, 2024

An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated attacker to execute arbitrary c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5424

Published Jun 7, 2024

The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed untrusted input into…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48709

Published Apr 15, 2024

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3214

Published Apr 9, 2024

The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attac…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25007

Published Apr 4, 2024

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a C…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29375

Published Apr 4, 2024

CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Cu…

CVSS 9.8 · Critical

CVE-2023-35899

Published Mar 21, 2024

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV In…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28111

Published Mar 6, 2024

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45597

Published Mar 5, 2024

A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “exp…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24337

Published Feb 12, 2024

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to i…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47022

Published Feb 6, 2024

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31295

Published Dec 29, 2023

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31294

Published Dec 29, 2023

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50448

Published Dec 28, 2023

In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV expor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42004

Published Nov 28, 2023

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file c…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 298 CVEsPage 4 of 12