VYPR

studio-backend-bundle

by Pimcore

CVEs (3)

  • CVE-2026-55207Jul 9, 2026
    risk 0.00cvss epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl.…

  • CVE-2026-55208Jul 9, 2026
    risk 0.00cvss epss 0.00

    Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the DateFilter column key parameter. The POST…

  • CVE-2026-55212Jul 9, 2026
    risk 0.00cvss epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by the objects permission instead of the…