PatchSiren

Tendenci CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tendenci CVE published 2026-01-28

CVE-2020-36962

CVE-2020-36962 is a CSV formula injection vulnerability in Tendenci 12.3.1. Attackers can inject malicious formulas in the contact form message field, which can lead to arbitrary command execution when the CSV is opened in spreadsheet applications. This vulnerability requires verification and remediation to prevent potential attacks. The vulnerability allows attackers to submit crafted payloads like '=10+ [truncated]