Description An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. Remediation References CVE-2019-12765 Related Vulnerabilities WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce SQL Injection (5.7.23) WordPress 2.0.4 Multiple Security Vulnerabilities (2.0.4) WordPress Plugin YaMaps for WordPress Cross-Site Scripting (0.6.25) MediaWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-23172) concrete5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-9526) Severity Critical Classification CVE-2019-12765 CWE-1236 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities