MEDIUM
Tendenci
CVE published 2026-01-28
CVE-2020-36962
CVE-2020-36962 is a CSV formula injection vulnerability in Tendenci 12.3.1. Attackers can inject malicious formulas in the contact form message field, which can lead to arbitrary command execution when the CSV is opened in spreadsheet applications. This vulnerability requires verification and remediation to prevent potential attacks. The vulnerability allows attackers to submit crafted payloads like '=10+ [truncated]