CVE-2019-14352: Joget Worfklow

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applications

Affected products

  • Joget Worfklow: version 6.0.20 only

Published 2019-07-28. Last modified 2026-06-17.