Total
312 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-16308 | 1 Ninjaforms | 1 Ninja Forms | 2026-06-17 | 6.8 MEDIUM | 8.6 HIGH |
| The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | |||||
| CVE-2018-16275 | 1 Opswat | 1 Metadefender | 2026-06-17 | 6.8 MEDIUM | 7.8 HIGH |
| OPSWAT MetaDefender before v4.11.2 allows CSV injection. | |||||
| CVE-2018-15571 | 1 Export Users To Csv Project | 1 Export Users To Csv | 2026-06-17 | 6.8 MEDIUM | 8.6 HIGH |
| The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. | |||||
| CVE-2018-15474 | 1 Dokuwiki | 1 Dokuwiki | 2026-06-17 | 6.8 MEDIUM | 9.6 CRITICAL |
| CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled in a CSV export. NOTE: the vendor has stated "this is not a security problem in DokuWiki. | |||||
| CVE-2018-12244 | 1 Symantec | 1 Endpoint Protection | 2026-06-17 | 6.8 MEDIUM | 6.3 MEDIUM |
| SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files. | |||||
| CVE-2018-11652 | 1 Cirt.net | 1 Nikto | 2026-06-17 | 10.0 HIGH | 9.8 CRITICAL |
| CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. | |||||
| CVE-2018-11526 | 1 Webtoffee | 1 Wordpress Comments Import And Export | 2026-06-17 | 6.8 MEDIUM | 7.8 HIGH |
| The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | |||||
| CVE-2018-11525 | 1 Algolplus | 1 Advanced Order Export For Woocommerce | 2026-06-17 | 6.8 MEDIUM | 7.8 HIGH |
| The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | |||||
| CVE-2018-10504 | 1 Web-dorado | 1 Form Maker | 2026-06-17 | 6.8 MEDIUM | 7.8 HIGH |
| The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. | |||||
| CVE-2018-10258 | 1 Codeslab | 1 Shopy Point Of Sale | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |||||
| CVE-2018-10257 | 1 Hrsale Project | 1 Hrsale | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |||||
| CVE-2018-10255 | 1 Clustercoding | 1 Blog Master Pro | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |||||
