Pimcore
by Pimcore
Source repositories
CVEs (141)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3820 | Hig | 0.40 | 7.2 | 0.01 | Jul 21, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-3673 | Hig | 0.40 | 7.2 | 0.01 | Jul 14, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24. | ||
| CVE-2026-45704 | Hig | 0.39 | — | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC… | ||
| CVE-2026-5394 | Hig | 0.39 | — | 0.00 | Apr 27, 2026 | An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3. | ||
| CVE-2021-23340 | Hig | 0.39 | 7.1 | 0.01 | Feb 18, 2021 | This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this… | ||
| CVE-2026-55072 | hig | 0.38 | — | — | Aug 13, 2026 | ### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw… | ||
| CVE-2018-14059 | Med | 0.38 | 5.4 | 0.03 | Aug 24, 2018 | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions. | ||
| CVE-2026-45703 | Med | 0.35 | 6.4 | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves… | ||
| CVE-2026-5362 | Med | 0.35 | 5.4 | 0.00 | Apr 27, 2026 | An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3. | ||
| CVE-2023-5192 | Med | 0.35 | 6.5 | 0.01 | Sep 27, 2023 | Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0. | ||
| CVE-2023-3819 | Med | 0.35 | 6.5 | 0.01 | Jul 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-30855 | Med | 0.35 | 6.5 | 0.01 | May 8, 2023 | Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.… | ||
| CVE-2023-2336 | Med | 0.35 | 6.5 | 0.01 | Apr 27, 2023 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2022-0665 | Med | 0.35 | 6.5 | 0.02 | Feb 22, 2022 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. | ||
| CVE-2023-38708 | Med | 0.34 | 6.3 | 0.01 | Aug 4, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by… | ||
| CVE-2023-3822 | Med | 0.33 | 6.1 | 0.01 | Jul 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-2341 | Med | 0.33 | 6.1 | 0.01 | Apr 27, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-28438 | Med | 0.33 | 6.2 | 0.01 | Mar 22, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject… | ||
| CVE-2023-28429 | Med | 0.33 | 6.1 | 0.01 | Mar 20, 2023 | Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through… | ||
| CVE-2023-28106 | Med | 0.33 | 6.1 | 0.01 | Mar 16, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch… |
- risk 0.40cvss 7.2epss 0.01
SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.40cvss 7.2epss 0.01
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24.
- risk 0.39cvss —epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC…
- risk 0.39cvss —epss 0.00
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.
- risk 0.39cvss 7.1epss 0.01
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this…
- risk 0.38cvss —epss —
### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw…
- risk 0.38cvss 5.4epss 0.03
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
- risk 0.35cvss 6.4epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves…
- risk 0.35cvss 5.4epss 0.00
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.
- risk 0.35cvss 6.5epss 0.01
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.
- risk 0.35cvss 6.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.35cvss 6.5epss 0.01
Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.…
- risk 0.35cvss 6.5epss 0.01
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.35cvss 6.5epss 0.02
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
- risk 0.34cvss 6.3epss 0.01
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by…
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.33cvss 6.2epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject…
- risk 0.33cvss 6.1epss 0.01
Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through…
- risk 0.33cvss 6.1epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch…
Page 3 of 8