Cyber Resilience

CWE · MITRE source

CWE-1236Improper Neutralization of Formula Elements in a CSV File

Abstraction: Base · CVEs in our corpus: 303

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Last updated: 21 August 2026 22:22 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-15 Information Output Filtering
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.2.10

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-33256 9.18.80.79002021-08-09
CVE-2018-11652 8.79.80.24442018-06-01
CVE-2019-12765 8.29.80.10492019-06-11
CVE-2020-369628.29.80.10682026-01-28
CVE-2020-9347 8.19.80.07792020-03-16
CVE-2020-11548 7.99.80.05172020-04-05
CVE-2018-20752 7.89.80.03432019-02-04
CVE-2020-7947 7.89.80.02842020-04-01
CVE-2020-22276 7.89.80.03022020-11-04
CVE-2019-4521 7.79.80.02612019-12-10
CVE-2019-0403 7.79.80.02092019-12-11
CVE-2021-38180 7.79.80.02052021-10-12
CVE-2022-0142 7.79.80.02692022-04-12
CVE-2018-8092 7.69.80.01692018-04-18
CVE-2019-13144 7.69.80.01842019-07-05
CVE-2019-16184 7.69.80.01712019-09-09
CVE-2020-22274 7.69.80.01632020-11-04
CVE-2021-3188 7.69.80.01792021-01-26
CVE-2022-26249 7.69.80.01882022-03-24
CVE-2022-28481 7.69.80.01732022-05-01
CVE-2022-3393 7.69.80.01292022-10-25
CVE-2022-3574 7.69.80.01322022-11-14
CVE-2020-10131 7.69.80.01522023-09-06
CVE-2024-29375 7.69.80.01462024-04-04
CVE-2018-9035 7.59.60.07442018-04-04