VYPR

Pimcore

by Pimcore

Source repositories

CVEs (141)

  • CVE-2019-10867HigApr 4, 2019
    risk 0.59cvss 8.8epss 0.69

    An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…

  • CVE-2023-25240HigFeb 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.

  • CVE-2022-39365CriOct 27, 2022
    risk 0.57cvss 9.8epss 0.02

    Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…

  • CVE-2019-18985CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks brute force protection for the 2FA token.

  • CVE-2019-18981CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.

  • CVE-2023-1578HigMar 22, 2023
    risk 0.55cvss 8.8epss 0.63

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

  • CVE-2018-14057HigAug 17, 2018
    risk 0.53cvss 8.8epss 0.03

    Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

  • CVE-2021-4139CriDec 21, 2021
    risk 0.52cvss 9.0epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-44741HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a…

  • CVE-2026-44739HigJul 17, 2026
    risk 0.50cvss 8.7epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through…

  • CVE-2026-23492HigJan 14, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL…

  • CVE-2025-27617HigMar 11, 2025
    risk 0.50cvss 8.8epss 0.00

    Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.

  • CVE-2023-47637HigNov 15, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One…

  • CVE-2023-2984HigMay 30, 2023
    risk 0.50cvss 8.8epss 0.01

    Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

  • CVE-2023-2983HigMay 30, 2023
    risk 0.50cvss 8.8epss 0.01

    Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.

  • CVE-2023-30850HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.

  • CVE-2023-30849HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.

  • CVE-2023-30848HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually.

  • CVE-2023-2338HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2022-0258HigJan 17, 2022
    risk 0.50cvss 8.8epss 0.02

    pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

Page 1 of 8