CWE-1236 · 300 kayıt
Improper Neutralization of Formula Elements in a CSV File
Bu sınıftaki CVE’ler
300 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2021-33256İstismar yok | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unautzohocorp · manageengine adselfservice plus · CWE-1236 | Yüksek8,8 | — | %79,0 | 9 Ağu 2021 |
46Planlayın | CVE-2018-11652Kavram kanıtı | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTcirt.net · nikto · CWE-1236 | Kritik9,8 | — | %24,4 | 1 Haz 2018 |
42Planlayın | CVE-2019-12765Kavram kanıtı | An issue was discovered in Joomla! before 3.9.7.joomla · joomla\! · CWE-1236 | Kritik9,8 | — | %10,5 | 11 Haz 2019 |
41Planlayın | CVE-2020-9347İstismar yok | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by tzohocorp · manageengine password manager pro · CWE-1236 | Kritik9,8 | — | %7,8 | 16 Mar 2020 |
41Planlayın | CVE-2020-11548İstismar yok | The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula.search meter project · search meter · CWE-1236 | Kritik9,8 | — | %5,2 | 4 Nis 2020 |
40Planlayın | CVE-2018-9035Kavram kanıtı | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote atcontact-form-7-to-database-extension project · contact-form-7-to-database-extension · CWE-1236 | Kritik9,6 | — | %7,3 | 4 Nis 2018 |
40Planlayın | CVE-2022-3634İstismar yok | Contact Form 7 Database Addon < 1.2.6.5 - CSV Injectionciphercoin · contact form 7 database addon · CWE-1236 | Kritik9,8 | — | %3,9 | 21 Kas 2022 |
40Planlayın | CVE-2018-20752İstismar yok | An issue was discovered in Recon-ng before 4.9.5.recon-ng project · recon-ng · CWE-1236 | Kritik9,8 | — | %3,4 | 4 Şub 2019 |
40Planlayın | CVE-2020-22276İstismar yok | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.weformspro · weforms · CWE-1236 | Kritik9,8 | — | %3,0 | 4 Kas 2020 |
40Planlayın | CVE-2022-0142İstismar yok | Visual Form Builder < 3.0.6 - CSV Injectionvfbpro · visual form builder · CWE-1236 | Kritik9,8 | — | %2,9 | 12 Nis 2022 |
40Planlayın | CVE-2020-7947İstismar yok | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 · CWE-1236 | Kritik9,8 | — | %2,8 | 1 Nis 2020 |
40Planlayın | CVE-2019-4521İstismar yok | Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection.ibm · cloud pak system · CWE-1236 | Kritik9,8 | — | %2,6 | 10 Ara 2019 |
40Planlayın | CVE-2019-0403İstismar yok | SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading tosap · enable now · CWE-1236 | Kritik9,8 | — | %2,1 | 11 Ara 2019 |
40Planlayın | CVE-2021-38180İstismar yok | SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitatisap · business one · CWE-1236 | Kritik9,8 | — | %2,1 | 12 Eki 2021 |
40Planlayın | CVE-2022-26249İstismar yok | Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitivsurveyking project · surveyking · CWE-1236 | Kritik9,8 | — | %1,9 | 24 Mar 2022 |
40Planlayın | CVE-2019-13144Kavram kanıtı | myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection.mytinytodo · mytinytodo · CWE-1236 | Kritik9,8 | — | %1,8 | 5 Tem 2019 |
40Planlayın | CVE-2021-3188İstismar yok | phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.phplist · phplist · CWE-1236 | Kritik9,8 | — | %1,8 | 26 Oca 2021 |
40Planlayın | CVE-2022-28481İstismar yok | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.csv-safe project · csv-safe · CWE-1236 | Kritik9,8 | — | %1,8 | 1 May 2022 |
40Planlayın | CVE-2019-16184İstismar yok | A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey reslimesurvey · limesurvey · CWE-1236 | Kritik9,8 | — | %1,7 | 9 Eyl 2019 |
39İzleyin | CVE-2018-15474İstismar yok | CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier alldokuwiki · dokuwiki · CWE-1236 | Kritik9,6 | — | %3,3 | 7 Eyl 2018 |
39İzleyin | CVE-2018-8092İstismar yok | Mautic before 2.13.0 allows CSV injection.mautic · mautic · CWE-1236 | Kritik9,8 | — | %1,6 | 18 Nis 2018 |
39İzleyin | CVE-2020-22274İstismar yok | JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.jomsocial · jomsocial · CWE-1236 | Kritik9,8 | — | %1,6 | 4 Kas 2020 |
39İzleyin | CVE-2020-10131Kavram kanıtı | SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.searchblox · searchblox · CWE-1236 | Kritik9,8 | — | %1,6 | 6 Eyl 2023 |
39İzleyin | CVE-2022-3393İstismar yok | Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV Injectionbestwebsoft · post to csv · CWE-1236 | Kritik9,8 | — | %1,5 | 25 Eki 2022 |
39İzleyin | CVE-2024-29375Kavram kanıtı | CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to tCWE-1236 | Kritik9,8 | — | %1,5 | 4 Nis 2024 |
- CVE-2021-3325659Planlayın
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unaut
YüksekCVSS 8,8İstismar yokEPSS %79zohocorp · manageengine adselfservice plus9 Ağu 2021
- CVE-2018-1165246Planlayın
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HT
KritikCVSS 9,8Kavram kanıtıEPSS %24cirt.net · nikto1 Haz 2018
- CVE-2019-1276542Planlayın
An issue was discovered in Joomla! before 3.9.7.
KritikCVSS 9,8Kavram kanıtıEPSS %10joomla · joomla\!11 Haz 2019
- CVE-2020-934741Planlayın
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by t
KritikCVSS 9,8İstismar yokEPSS %8zohocorp · manageengine password manager pro16 Mar 2020
- CVE-2020-1154841Planlayın
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula.
KritikCVSS 9,8İstismar yokEPSS %5search meter project · search meter4 Nis 2020
- CVE-2018-903540Planlayın
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote at
KritikCVSS 9,6Kavram kanıtıEPSS %7contact-form-7-to-database-extension project · contact-form-7-to-database-extension4 Nis 2018
- CVE-2022-363440Planlayın
Contact Form 7 Database Addon < 1.2.6.5 - CSV Injection
KritikCVSS 9,8İstismar yokEPSS %4ciphercoin · contact form 7 database addon21 Kas 2022
- CVE-2018-2075240Planlayın
An issue was discovered in Recon-ng before 4.9.5.
KritikCVSS 9,8İstismar yokEPSS %3recon-ng project · recon-ng4 Şub 2019
- CVE-2020-2227640Planlayın
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
KritikCVSS 9,8İstismar yokEPSS %3weformspro · weforms4 Kas 2020
- CVE-2022-014240Planlayın
Visual Form Builder < 3.0.6 - CSV Injection
KritikCVSS 9,8İstismar yokEPSS %3vfbpro · visual form builder12 Nis 2022
- CVE-2020-794740Planlayın
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
KritikCVSS 9,8İstismar yokEPSS %3auth0 · login by auth01 Nis 2020
- CVE-2019-452140Planlayın
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection.
KritikCVSS 9,8İstismar yokEPSS %3ibm · cloud pak system10 Ara 2019
- CVE-2019-040340Planlayın
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to
KritikCVSS 9,8İstismar yokEPSS %2sap · enable now11 Ara 2019
- CVE-2021-3818040Planlayın
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitati
KritikCVSS 9,8İstismar yokEPSS %2sap · business one12 Eki 2021
- CVE-2022-2624940Planlayın
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitiv
KritikCVSS 9,8İstismar yokEPSS %2surveyking project · surveyking24 Mar 2022
- CVE-2019-1314440Planlayın
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection.
KritikCVSS 9,8Kavram kanıtıEPSS %2mytinytodo · mytinytodo5 Tem 2019
- CVE-2021-318840Planlayın
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
KritikCVSS 9,8İstismar yokEPSS %2phplist · phplist26 Oca 2021
- CVE-2022-2848140Planlayın
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
KritikCVSS 9,8İstismar yokEPSS %2csv-safe project · csv-safe1 May 2022
- CVE-2019-1618440Planlayın
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey res
KritikCVSS 9,8İstismar yokEPSS %2limesurvey · limesurvey9 Eyl 2019
- CVE-2018-1547439İzleyin
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier all
KritikCVSS 9,6İstismar yokEPSS %3dokuwiki · dokuwiki7 Eyl 2018
- CVE-2018-809239İzleyin
Mautic before 2.13.0 allows CSV injection.
KritikCVSS 9,8İstismar yokEPSS %2mautic · mautic18 Nis 2018
- CVE-2020-2227439İzleyin
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
KritikCVSS 9,8İstismar yokEPSS %2jomsocial · jomsocial4 Kas 2020
- CVE-2020-1013139İzleyin
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %2searchblox · searchblox6 Eyl 2023
- CVE-2022-339339İzleyin
Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV Injection
KritikCVSS 9,8İstismar yokEPSS %1bestwebsoft · post to csv25 Eki 2022
- CVE-2024-2937539İzleyin
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to t
KritikCVSS 9,8Kavram kanıtıEPSS %14 Nis 2024