Total
213 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10504 | 1 Web-dorado | 1 Form Maker | 2020-08-24 | 6.8 MEDIUM | 7.8 HIGH |
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | |||||
CVE-2019-13144 | 1 Mytinytodo | 1 Mytinytodo | 2020-08-24 | 7.5 HIGH | 9.8 CRITICAL |
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5. | |||||
CVE-2019-6187 | 1 Lenovo | 42 Thinksystem Sr670, Thinkagile 7d1h, Thinkagile 7x82 and 39 more | 2020-08-24 | 4.0 MEDIUM | 6.5 MEDIUM |
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server. | |||||
CVE-2018-15571 | 1 Export Users To Csv Project | 1 Export Users To Csv | 2020-08-24 | 6.8 MEDIUM | 8.6 HIGH |
The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. | |||||
CVE-2018-20468 | 1 Sahipro | 1 Sahi Pro | 2020-08-24 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution. | |||||
CVE-2018-9137 | 1 Open-audit | 1 Open-audit | 2020-08-24 | 3.5 LOW | 6.8 MEDIUM |
Open-AudIT before 2.2 has CSV Injection. | |||||
CVE-2018-16308 | 1 Ninjaforms | 1 Ninja Forms | 2020-08-24 | 6.8 MEDIUM | 8.6 HIGH |
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | |||||
CVE-2018-16651 | 1 Phpmyfaq | 1 Phpmyfaq | 2020-08-24 | 9.0 HIGH | 7.2 HIGH |
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports. | |||||
CVE-2018-10258 | 1 Codeslab | 1 Shopy Point Of Sale | 2020-08-24 | 6.5 MEDIUM | 8.8 HIGH |
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |||||
CVE-2018-10255 | 1 Clustercoding | 1 Blog Master Pro | 2020-08-24 | 6.5 MEDIUM | 8.8 HIGH |
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |||||
CVE-2019-16184 | 1 Limesurvey | 1 Limesurvey | 2020-08-24 | 7.5 HIGH | 9.8 CRITICAL |
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file. | |||||
CVE-2019-13181 | 1 Solarwinds | 1 Serv-u Ftp Server | 2020-08-24 | 4.0 MEDIUM | 6.5 MEDIUM |
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. | |||||
CVE-2018-16275 | 1 Opswat | 1 Metadefender | 2020-08-24 | 6.8 MEDIUM | 7.8 HIGH |
OPSWAT MetaDefender before v4.11.2 allows CSV injection. |