Tendenci is Vulnerable to CSV Formula Injection through its Contact Form Message Field
Moderate severity
GitHub Reviewed
Published
Jan 28, 2026
to the GitHub Advisory Database
•
Updated Jun 9, 2026
Description
Published by the National Vulnerability Database
Jan 28, 2026
Published to the GitHub Advisory Database
Jan 28, 2026
Reviewed
Jun 9, 2026
Last updated
Jun 9, 2026
Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.
References