VYPR

Pimcore

by Pimcore

Source repositories

CVEs (141)

  • CVE-2019-16318HigSep 14, 2019
    risk 0.50cvss 8.8epss 0.01

    In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and…

  • CVE-2019-16317HigSep 14, 2019
    risk 0.50cvss 8.8epss 0.02

    In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory,…

  • CVE-2026-23493HigJan 15, 2026
    risk 0.49cvss 8.6epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed…

  • CVE-2022-1429HigApr 22, 2022
    risk 0.47cvss 7.5epss 0.64

    SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data

  • CVE-2026-45260HigJul 17, 2026
    risk 0.46cvss 8.1epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php,…

  • CVE-2023-23937HigFeb 3, 2023
    risk 0.46cvss 8.2epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by…

  • CVE-2026-45162HigJul 17, 2026
    risk 0.45cvss 8.0epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including…

  • CVE-2023-28108HigMar 16, 2023
    risk 0.44cvss 7.9epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper…

  • CVE-2022-0263HigJan 18, 2022
    risk 0.44cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2024-32871HigJun 4, 2024
    risk 0.42cvss 7.5epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in…

  • CVE-2022-31092HigJun 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default. The actual issue…

  • CVE-2022-1339HigApr 13, 2022
    risk 0.42cvss 7.5epss 0.05

    SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

  • CVE-2022-1219HigApr 8, 2022
    risk 0.42cvss 7.5epss 0.01

    SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

  • CVE-2022-0565HigFeb 14, 2022
    risk 0.42cvss 7.6epss 0.01

    Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.

  • CVE-2021-31869MedAug 4, 2021
    risk 0.42cvss 6.5epss 0.01

    Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.

  • CVE-2021-31867MedAug 4, 2021
    risk 0.42cvss 6.5epss 0.01

    Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.

  • CVE-2019-10763MedNov 18, 2019
    risk 0.42cvss 6.5epss 0.01

    pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a…

  • CVE-2019-18986HigNov 15, 2019
    risk 0.42cvss 7.5epss 0.01

    Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.

  • CVE-2018-14058MedAug 17, 2018
    risk 0.41cvss 6.5epss 0.29

    Pimcore before 5.3.0 allows SQL Injection via the REST web service API.

  • CVE-2026-11407HigJun 17, 2026
    risk 0.40cvss 7.2epss 0.01

    Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig…

Page 2 of 8