People love spreadsheets. Macros and formulas are an easy way for non-coders to construct simple programs with a visual mini-database. Because of the widespread, everyday use of spreadsheets, people tend to trust them. Many applications also offer interaction via spreadsheets/CSV files (e.g. upload multiple lines, download as a spreadsheet, etc.). The popularity, implicit trust, integration into web applications, and extensive functionality combine to make a powerful vector of attack for red teams. This talk focuses on web app/spreadsheet interactions and how malicious actors could take advantage of client- and server-side coding issues to perform attacks ranging from XSS to RCE using spreadsheets.