Total
213 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-25983 | 1 Logon | 1 Kb Support | 2025-02-11 | N/A | 8.8 HIGH |
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84. | |||||
CVE-2023-46400 | 1 Kwhotel | 1 Kwhotel | 2025-02-07 | N/A | 9.8 CRITICAL |
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. | |||||
CVE-2019-16120 | 1 Liquidweb | 1 Event Tickets | 2025-02-07 | 6.5 MEDIUM | 8.8 HIGH |
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. | |||||
CVE-2023-48709 | 1 Combodo | 1 Itop | 2025-02-06 | N/A | 8.0 HIGH |
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0. | |||||
CVE-2023-46401 | 1 Kwhotel | 1 Kwhotel | 2025-02-04 | N/A | 9.8 CRITICAL |
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. | |||||
CVE-2023-25348 | 1 Churchcrm | 1 Churchcrm | 2025-02-04 | N/A | 7.8 HIGH |
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file. | |||||
CVE-2023-29918 | 1 Rosariosis | 1 Rosariosis | 2025-01-30 | N/A | 5.4 MEDIUM |
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. | |||||
CVE-2024-3214 | 1 Relevanssi | 1 Relevanssi | 2025-01-28 | N/A | 9.8 CRITICAL |
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | |||||
CVE-2024-22063 | 1 Zte | 1 Zenic One R58 | 2025-01-28 | N/A | 9.0 CRITICAL |
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices. | |||||
CVE-2023-33410 | 1 Minical | 1 Minical | 2025-01-08 | N/A | 8.8 HIGH |
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on the Customer Name field in the Accounting module that is used to construct a CSV file. | |||||
CVE-2018-11525 | 1 Algolplus | 1 Advanced Order Export For Woocommerce | 2024-11-20 | 6.8 MEDIUM | 7.8 HIGH |
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | |||||
CVE-2024-24337 | 1 Koha | 1 Koha | 2024-10-16 | N/A | 8.0 HIGH |
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components. | |||||
CVE-2019-17661 | 1 Admincolumns | 1 Admin Columns | 2024-10-15 | 9.0 HIGH | 8.8 HIGH |
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC. | |||||
CVE-2021-38963 | 3 Ibm, Linux, Microsoft | 3 Aspera Console, Linux Kernel, Windows | 2024-09-30 | N/A | 8.0 HIGH |
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |||||
CVE-2024-27320 | 1 Refuel | 1 Autolabel | 2024-09-23 | N/A | 7.8 HIGH |
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it. | |||||
CVE-2024-27321 | 1 Refuel | 1 Autolabel | 2024-09-20 | N/A | 7.8 HIGH |
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it. | |||||
CVE-2022-27858 | 1 Activity Log Project | 1 Activity Log | 2024-09-16 | N/A | 9.8 CRITICAL |
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress. | |||||
CVE-2024-27785 | 1 Fortinet | 1 Fortiaiops | 2024-09-09 | N/A | 6.5 MEDIUM |
An improper neutralization of formula elements in a CSV File vulnerability [CWE-1236] in FortiAIOps version 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports. | |||||
CVE-2023-23678 | 1 Wpeka | 1 Wp Cookie Consent | 2024-09-05 | N/A | 7.2 HIGH |
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ).This issue affects WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): from n/a through 2.2.5. | |||||
CVE-2023-22719 | 1 Givewp | 1 Givewp | 2024-09-05 | N/A | 9.8 CRITICAL |
Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1. |