VYPR

Pimcore

by Pimcore

Source repositories

CVEs (141)

  • CVE-2023-3820HigJul 21, 2023
    risk 0.40cvss 7.2epss 0.01

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-3673HigJul 14, 2023
    risk 0.40cvss 7.2epss 0.01

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.

  • CVE-2026-45704HigJul 17, 2026
    risk 0.39cvss epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC…

  • CVE-2026-5394HigApr 27, 2026
    risk 0.39cvss epss 0.00

    An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

  • CVE-2021-23340HigFeb 18, 2021
    risk 0.39cvss 7.1epss 0.01

    This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this…

  • CVE-2026-55072higAug 13, 2026
    risk 0.38cvss epss

    ### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw…

  • CVE-2018-14059MedAug 24, 2018
    risk 0.38cvss 5.4epss 0.03

    Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.

  • CVE-2026-45703MedJul 17, 2026
    risk 0.35cvss 6.4epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves…

  • CVE-2026-5362MedApr 27, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

  • CVE-2023-5192MedSep 27, 2023
    risk 0.35cvss 6.5epss 0.01

    Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.

  • CVE-2023-3819MedJul 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-30855MedMay 8, 2023
    risk 0.35cvss 6.5epss 0.01

    Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.…

  • CVE-2023-2336MedApr 27, 2023
    risk 0.35cvss 6.5epss 0.01

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2022-0665MedFeb 22, 2022
    risk 0.35cvss 6.5epss 0.02

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

  • CVE-2023-38708MedAug 4, 2023
    risk 0.34cvss 6.3epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by…

  • CVE-2023-3822MedJul 21, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-2341MedApr 27, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-28438MedMar 22, 2023
    risk 0.33cvss 6.2epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject…

  • CVE-2023-28429MedMar 20, 2023
    risk 0.33cvss 6.1epss 0.01

    Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through…

  • CVE-2023-28106MedMar 16, 2023
    risk 0.33cvss 6.1epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch…

Page 3 of 8