Threats Tagged 'cwe-1236'
View all threats tagged with 'cwe-1236'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1236'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-47705: CWE-1236: Improper Neutralization of Formula Elements in a CSV File in baptisteArno typebot.ioCVE-2026-47705 0 TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue. Join the discussion | CVE Database V5 | 08/11/2026, 17:16:12 UTC Added: 08/11/2026, 17:42:02 UTC |
CVE-2026-54243: CWE-1236: Improper Neutralization of Formula Elements in a CSV File in statamic cmsCVE-2026-54243 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value beginning with a formula trigger character, such as =, +, -, or @, could be interpreted as a live formula when a Control Panel user opens the export in a spreadsheet application. Form submissions can come from unauthenticated front-end visitors, so the malicious value can be supplied by an anonymous user and is later triggered by an editor opening the export. This issue is fixed in versions 5.73.24 and 6.20.1. Join the discussion | CVE Database V5 | 07/17/2026, 20:24:53 UTC Added: 07/18/2026, 11:08:26 UTC |
CVE-2026-14846: CWE-1236 Improper neutralization of formula elements in a CSV file in PrestaShop The firmwareCVE-2026-14846 0 In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported using the ‘Get my data in CSV’ tool. Successful exploitation of this vulnerability could facilitate unauthorised access to the victim’s personal data. Join the discussion | CVE Database V5 | 07/13/2026, 09:31:42 UTC Added: 07/13/2026, 10:03:12 UTC |
Showing 1 to 3 of 3 results