Pimcore
by Pimcore
Source repositories
CVEs (141)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16318 | Hig | 0.50 | 8.8 | 0.01 | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and… | ||
| CVE-2019-16317 | Hig | 0.50 | 8.8 | 0.02 | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory,… | ||
| CVE-2026-23493 | Hig | 0.49 | 8.6 | 0.00 | Jan 15, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed… | ||
| CVE-2022-1429 | Hig | 0.47 | 7.5 | 0.64 | Apr 22, 2022 | SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data | ||
| CVE-2026-45260 | Hig | 0.46 | 8.1 | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php,… | ||
| CVE-2023-23937 | Hig | 0.46 | 8.2 | 0.00 | Feb 3, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by… | ||
| CVE-2026-45162 | Hig | 0.45 | 8.0 | 0.01 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including… | ||
| CVE-2023-28108 | Hig | 0.44 | 7.9 | 0.01 | Mar 16, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper… | ||
| CVE-2022-0263 | Hig | 0.44 | 7.8 | 0.01 | Jan 18, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7. | ||
| CVE-2024-32871 | Hig | 0.42 | 7.5 | 0.01 | Jun 4, 2024 | Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in… | ||
| CVE-2022-31092 | Hig | 0.42 | 7.5 | 0.01 | Jun 27, 2022 | Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default. The actual issue… | ||
| CVE-2022-1339 | Hig | 0.42 | 7.5 | 0.05 | Apr 13, 2022 | SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data | ||
| CVE-2022-1219 | Hig | 0.42 | 7.5 | 0.01 | Apr 8, 2022 | SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data | ||
| CVE-2022-0565 | Hig | 0.42 | 7.6 | 0.01 | Feb 14, 2022 | Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1. | ||
| CVE-2021-31869 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2021 | Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product. | ||
| CVE-2021-31867 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2021 | Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product. | ||
| CVE-2019-10763 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2019 | pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a… | ||
| CVE-2019-18986 | Hig | 0.42 | 7.5 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users. | ||
| CVE-2018-14058 | Med | 0.41 | 6.5 | 0.29 | Aug 17, 2018 | Pimcore before 5.3.0 allows SQL Injection via the REST web service API. | ||
| CVE-2026-11407 | Hig | 0.40 | 7.2 | 0.01 | Jun 17, 2026 | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig… |
- risk 0.50cvss 8.8epss 0.01
In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and…
- risk 0.50cvss 8.8epss 0.02
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory,…
- risk 0.49cvss 8.6epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed…
- risk 0.47cvss 7.5epss 0.64
SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data
- risk 0.46cvss 8.1epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php,…
- risk 0.46cvss 8.2epss 0.00
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by…
- risk 0.45cvss 8.0epss 0.01
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including…
- risk 0.44cvss 7.9epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL if the developer is using this methods with input data and not doing proper…
- risk 0.44cvss 7.8epss 0.01
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
- risk 0.42cvss 7.5epss 0.01
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in…
- risk 0.42cvss 7.5epss 0.01
Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make querying data easier. This listing classes also allow to order or group the results based on one or more columns which should be quoted by default. The actual issue…
- risk 0.42cvss 7.5epss 0.05
SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data
- risk 0.42cvss 7.5epss 0.01
SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data
- risk 0.42cvss 7.6epss 0.01
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
- risk 0.42cvss 6.5epss 0.01
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.
- risk 0.42cvss 6.5epss 0.01
Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.
- risk 0.42cvss 6.5epss 0.01
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a…
- risk 0.42cvss 7.5epss 0.01
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
- risk 0.41cvss 6.5epss 0.29
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
- risk 0.40cvss 7.2epss 0.01
Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig…
Page 2 of 8