Filters apply as you choose them.
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.