Vulnerabilities > Improper Neutralization of Formula Elements in a CSV File

DATE CVE VULNERABILITY TITLE RISK
2025-01-23 CVE-2023-46400 Improper Neutralization of Formula Elements in a CSV File vulnerability in Kwhotel 0.47
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
network
low complexity
kwhotel CWE-1236
critical
9.8
2025-01-23 CVE-2023-46401 Improper Neutralization of Formula Elements in a CSV File vulnerability in Kwhotel 0.47
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
network
low complexity
kwhotel CWE-1236
critical
9.8
2024-12-30 CVE-2024-22063 Improper Neutralization of Formula Elements in a CSV File vulnerability in ZTE Zenic ONE R58
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability.
network
low complexity
zte CWE-1236
critical
9.0
2024-10-18 CVE-2024-47485 Improper Neutralization of Formula Elements in a CSV File vulnerability in Hikvision Hikcentral Master
There is a CSV injection vulnerability in some HikCentral Master Lite versions.
network
low complexity
hikvision CWE-1236
critical
9.8
2024-09-25 CVE-2021-38963 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Aspera Console 3.4.0/3.4.1/3.4.2
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability.
network
low complexity
ibm CWE-1236
8.0
2024-09-12 CVE-2024-27320 Improper Neutralization of Formula Elements in a CSV File vulnerability in Refuel Autolabel
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files.
local
low complexity
refuel CWE-1236
7.8
2024-09-12 CVE-2024-27321 Improper Neutralization of Formula Elements in a CSV File vulnerability in Refuel Autolabel
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files.
local
low complexity
refuel CWE-1236
7.8
2024-08-06 CVE-2024-41226 Improper Neutralization of Formula Elements in a CSV File vulnerability in Automationanywhere Automation 360 21094
A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload.
local
low complexity
automationanywhere CWE-1236
7.8
2024-06-18 CVE-2023-5527 Improper Neutralization of Formula Elements in a CSV File vulnerability in Businessdirectoryplugin Business Directory
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file.
network
low complexity
businessdirectoryplugin CWE-1236
8.0
2024-06-07 CVE-2023-5424 Improper Neutralization of Formula Elements in a CSV File vulnerability in Westguardsolutions WS Form
The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217.
network
low complexity
westguardsolutions CWE-1236
8.8