İçeriğe atla
Noroxi

CWE-1236 · 300 kayıt

Improper Neutralization of Formula Elements in a CSV File

Bu sınıftaki CVE’ler

300 kayıt

  • CVE-2021-33256
    59Planlayın

    A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unaut

    YüksekCVSS 8,8İstismar yokEPSS %79

    zohocorp · manageengine adselfservice plus9 Ağu 2021

  • CVE-2018-11652
    46Planlayın

    CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HT

    KritikCVSS 9,8Kavram kanıtıEPSS %24

    cirt.net · nikto1 Haz 2018

  • CVE-2019-12765
    42Planlayın

    An issue was discovered in Joomla! before 3.9.7.

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    joomla · joomla\!11 Haz 2019

  • CVE-2020-9347
    41Planlayın

    Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by t

    KritikCVSS 9,8İstismar yokEPSS %8

    zohocorp · manageengine password manager pro16 Mar 2020

  • CVE-2020-11548
    41Planlayın

    The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula.

    KritikCVSS 9,8İstismar yokEPSS %5

    search meter project · search meter4 Nis 2020

  • CVE-2018-9035
    40Planlayın

    CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote at

    KritikCVSS 9,6Kavram kanıtıEPSS %7

    contact-form-7-to-database-extension project · contact-form-7-to-database-extension4 Nis 2018

  • CVE-2022-3634
    40Planlayın

    Contact Form 7 Database Addon < 1.2.6.5 - CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %4

    ciphercoin · contact form 7 database addon21 Kas 2022

  • CVE-2018-20752
    40Planlayın

    An issue was discovered in Recon-ng before 4.9.5.

    KritikCVSS 9,8İstismar yokEPSS %3

    recon-ng project · recon-ng4 Şub 2019

  • CVE-2020-22276
    40Planlayın

    WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

    KritikCVSS 9,8İstismar yokEPSS %3

    weformspro · weforms4 Kas 2020

  • CVE-2022-0142
    40Planlayın

    Visual Form Builder < 3.0.6 - CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %3

    vfbpro · visual form builder12 Nis 2022

  • CVE-2020-7947
    40Planlayın

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.

    KritikCVSS 9,8İstismar yokEPSS %3

    auth0 · login by auth01 Nis 2020

  • CVE-2019-4521
    40Planlayın

    Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection.

    KritikCVSS 9,8İstismar yokEPSS %3

    ibm · cloud pak system10 Ara 2019

  • CVE-2019-0403
    40Planlayın

    SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to

    KritikCVSS 9,8İstismar yokEPSS %2

    sap · enable now11 Ara 2019

  • CVE-2021-38180
    40Planlayın

    SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitati

    KritikCVSS 9,8İstismar yokEPSS %2

    sap · business one12 Eki 2021

  • CVE-2022-26249
    40Planlayın

    Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitiv

    KritikCVSS 9,8İstismar yokEPSS %2

    surveyking project · surveyking24 Mar 2022

  • CVE-2019-13144
    40Planlayın

    myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    mytinytodo · mytinytodo5 Tem 2019

  • CVE-2021-3188
    40Planlayın

    phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.

    KritikCVSS 9,8İstismar yokEPSS %2

    phplist · phplist26 Oca 2021

  • CVE-2022-28481
    40Planlayın

    CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    csv-safe project · csv-safe1 May 2022

  • CVE-2019-16184
    40Planlayın

    A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey res

    KritikCVSS 9,8İstismar yokEPSS %2

    limesurvey · limesurvey9 Eyl 2019

  • CVE-2018-15474
    39İzleyin

    CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier all

    KritikCVSS 9,6İstismar yokEPSS %3

    dokuwiki · dokuwiki7 Eyl 2018

  • CVE-2018-8092
    39İzleyin

    Mautic before 2.13.0 allows CSV injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    mautic · mautic18 Nis 2018

  • CVE-2020-22274
    39İzleyin

    JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.

    KritikCVSS 9,8İstismar yokEPSS %2

    jomsocial · jomsocial4 Kas 2020

  • CVE-2020-10131
    39İzleyin

    SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    searchblox · searchblox6 Eyl 2023

  • CVE-2022-3393
    39İzleyin

    Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    bestwebsoft · post to csv25 Eki 2022

  • CVE-2024-29375
    39İzleyin

    CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to t

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    4 Nis 2024

Tüm zafiyet sınıfları