Vulnerabilities (CVE)

Filtered by CWE-1236
Total 213 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10504 1 Web-dorado 1 Form Maker 2020-08-24 6.8 MEDIUM 7.8 HIGH
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
CVE-2019-13144 1 Mytinytodo 1 Mytinytodo 2020-08-24 7.5 HIGH 9.8 CRITICAL
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
CVE-2019-6187 1 Lenovo 42 Thinksystem Sr670, Thinkagile 7d1h, Thinkagile 7x82 and 39 more 2020-08-24 4.0 MEDIUM 6.5 MEDIUM
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
CVE-2018-15571 1 Export Users To Csv Project 1 Export Users To Csv 2020-08-24 6.8 MEDIUM 8.6 HIGH
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
CVE-2018-20468 1 Sahipro 1 Sahi Pro 2020-08-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.
CVE-2018-9137 1 Open-audit 1 Open-audit 2020-08-24 3.5 LOW 6.8 MEDIUM
Open-AudIT before 2.2 has CSV Injection.
CVE-2018-16308 1 Ninjaforms 1 Ninja Forms 2020-08-24 6.8 MEDIUM 8.6 HIGH
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
CVE-2018-16651 1 Phpmyfaq 1 Phpmyfaq 2020-08-24 9.0 HIGH 7.2 HIGH
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
CVE-2018-10258 1 Codeslab 1 Shopy Point Of Sale 2020-08-24 6.5 MEDIUM 8.8 HIGH
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
CVE-2018-10255 1 Clustercoding 1 Blog Master Pro 2020-08-24 6.5 MEDIUM 8.8 HIGH
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
CVE-2019-16184 1 Limesurvey 1 Limesurvey 2020-08-24 7.5 HIGH 9.8 CRITICAL
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
CVE-2019-13181 1 Solarwinds 1 Serv-u Ftp Server 2020-08-24 4.0 MEDIUM 6.5 MEDIUM
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
CVE-2018-16275 1 Opswat 1 Metadefender 2020-08-24 6.8 MEDIUM 7.8 HIGH
OPSWAT MetaDefender before v4.11.2 allows CSV injection.