Pimcore
by Pimcore
Source repositories
CVEs (141)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10867 | Hig | 0.59 | 8.8 | 0.69 | Apr 4, 2019 | An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to… | ||
| CVE-2023-25240 | Hig | 0.57 | 8.8 | 0.01 | Feb 13, 2023 | An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code. | ||
| CVE-2022-39365 | Cri | 0.57 | 9.8 | 0.02 | Oct 27, 2022 | Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.… | ||
| CVE-2019-18985 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks brute force protection for the 2FA token. | ||
| CVE-2019-18981 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification. | ||
| CVE-2023-1578 | Hig | 0.55 | 8.8 | 0.63 | Mar 22, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. | ||
| CVE-2018-14057 | Hig | 0.53 | 8.8 | 0.03 | Aug 17, 2018 | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function. | ||
| CVE-2021-4139 | Cri | 0.52 | 9.0 | 0.01 | Dec 21, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2026-44741 | Hig | 0.50 | 8.8 | 0.00 | Aug 12, 2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a… | ||
| CVE-2026-44739 | Hig | 0.50 | 8.7 | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through… | ||
| CVE-2026-23492 | Hig | 0.50 | 8.8 | 0.00 | Jan 14, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL… | ||
| CVE-2025-27617 | Hig | 0.50 | 8.8 | 0.00 | Mar 11, 2025 | Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue. | ||
| CVE-2023-47637 | Hig | 0.50 | 8.8 | 0.01 | Nov 15, 2023 | Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One… | ||
| CVE-2023-2984 | Hig | 0.50 | 8.8 | 0.01 | May 30, 2023 | Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | ||
| CVE-2023-2983 | Hig | 0.50 | 8.8 | 0.01 | May 30, 2023 | Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23. | ||
| CVE-2023-30850 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. | ||
| CVE-2023-30849 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. | ||
| CVE-2023-30848 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually. | ||
| CVE-2023-2338 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2022-0258 | Hig | 0.50 | 8.8 | 0.02 | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command |
- risk 0.59cvss 8.8epss 0.69
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…
- risk 0.57cvss 8.8epss 0.01
An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.
- risk 0.57cvss 9.8epss 0.02
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
- risk 0.55cvss 8.8epss 0.63
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
- risk 0.53cvss 8.8epss 0.03
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
- risk 0.52cvss 9.0epss 0.01
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.50cvss 8.8epss 0.00
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a…
- risk 0.50cvss 8.7epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through…
- risk 0.50cvss 8.8epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL…
- risk 0.50cvss 8.8epss 0.00
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One…
- risk 0.50cvss 8.8epss 0.01
Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.
- risk 0.50cvss 8.8epss 0.01
Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually.
- risk 0.50cvss 8.8epss 0.01
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.50cvss 8.8epss 0.02
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Page 1 of 8