boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1236

Weakness type CWE-1236 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15150

Monthly trend

▄▇█▇

2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-187385.131.4Shlink CSV Formula Injection via Visit Export CLI
CVE-2026-477059.631.1TypeBot vulnerable to CSV injection in result export
CVE-2026-52428.823.1Code Injection in Mia Technologies' Pizzy Library
CVE-2026-148464.516.8Incorrect neutralisation in the PrestaShop firmware
CVE-2026-102482.016.4SourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supp…
CVE-2026-554524.814.6Snipe-IT: CSV formula injection in Activity Report export
CVE-2026-476936.913.9Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadshe…
CVE-2026-649556.113.3Velociraptor CSV Formula Injection in Export Pipeline
CVE-2025-526128.810.1HCL iControl was affected by Export CSV - CSV Injection vulnerability.
CVE-2026-542436.19.1Statamic: CSV formula injection in form submission exports
CVE-2026-501794.27.2Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
CVE-2026-96735.56.4
CVE-2026-410734.66.3RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Excel and si…
CVE-2026-658755.14.9
CVE-2026-466724.63.2Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `es…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
actualbudget2
baptistearno1
basercms users community1
bestpractical1
grokability1
hcl1
mia technology1
poweradmin1
prestashop1
rapid71
shlinkio1
sourcecodester1
statamic1