Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1236
Weakness type CWE-1236 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 27 | 27 | 0 |
Monthly trend
▃▅▅██▁
2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 8 · 2026-09 8 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47705 | 9.6 | 44.5 | — | TypeBot vulnerable to CSV injection in result export |
| CVE-2026-19501 | 8.8 | 44.4 | — | CVE-2026-19501 |
| CVE-2026-5242 | 8.8 | 42.0 | — | Code Injection in Mia Technologies' Pizzy Library |
| CVE-2026-18738 | 5.1 | 40.2 | — | Shlink CSV Formula Injection via Visit Export CLI |
| CVE-2026-55452 | 4.8 | 34.6 | — | Snipe-IT: CSV formula injection in Activity Report export |
| CVE-2026-14846 | 4.5 | 34.5 | — | Incorrect neutralisation in the PrestaShop firmware |
| CVE-2026-78209 | 8.4 | 32.9 | — | exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values |
| CVE-2026-86742 | 5.1 | 32.9 | — | Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report |
| CVE-2026-47693 | 6.9 | 29.2 | — | Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadshe… |
| CVE-2026-64955 | 6.1 | 28.0 | — | Velociraptor CSV Formula Injection in Export Pipeline |
| CVE-2026-79971 | 5.3 | 27.4 | — | — |
| CVE-2026-86745 | 5.1 | 27.3 | — | Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export |
| CVE-2026-76797 | 5.8 | 26.6 | — | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Gener… |
| CVE-2026-54243 | 6.1 | 24.9 | — | Statamic: CSV formula injection in form submission exports |
| CVE-2026-41073 | 4.6 | 19.5 | — | RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and si… |
| CVE-2026-50179 | 4.2 | 19.2 | — | Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields |
| CVE-2026-86257 | 4.8 | 18.3 | — | wger before 2.6 CSV Formula Injection via member export |
| CVE-2026-65875 | 5.1 | 16.3 | — | — |
| CVE-2026-10248 | 2.0 | 14.6 | — | SourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supp… |
| CVE-2026-9673 | 5.5 | 13.3 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| grokability | 3 |
| actualbudget | 2 |
| openclaw | 2 |
| baptistearno | 1 |
| basercms users community | 1 |
| bestpractical | 1 |
| dell | 1 |
| exceljs | 1 |
| hcl | 1 |
| hitachi energy | 1 |
| mia technology | 1 |
| mongodb | 1 |
| poweradmin | 1 |
| prestashop | 1 |
| rapid7 | 1 |