Pimcore
Products
10- 141 CVEs
- 15 CVEs
- 14 CVEs
- 9 CVEs
- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
168| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10867 | Hig | 0.59 | 8.8 | 0.69 | Apr 4, 2019 | An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to… | ||
| CVE-2026-72562 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without… | ||
| CVE-2023-25240 | Hig | 0.57 | 8.8 | 0.01 | Feb 13, 2023 | An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code. | ||
| CVE-2022-39365 | Cri | 0.57 | 9.8 | 0.02 | Oct 27, 2022 | Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.… | ||
| CVE-2019-18985 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks brute force protection for the 2FA token. | ||
| CVE-2019-18981 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2019 | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification. | ||
| CVE-2023-1578 | Hig | 0.55 | 8.8 | 0.63 | Mar 22, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. | ||
| CVE-2018-14057 | Hig | 0.53 | 8.8 | 0.03 | Aug 17, 2018 | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function. | ||
| CVE-2021-4139 | Cri | 0.52 | 9.0 | 0.01 | Dec 21, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2026-44741 | Hig | 0.50 | 8.8 | 0.00 | Aug 12, 2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a… | ||
| CVE-2026-44739 | Hig | 0.50 | 8.7 | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through… | ||
| CVE-2026-23492 | Hig | 0.50 | 8.8 | 0.00 | Jan 14, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL… | ||
| CVE-2025-27617 | Hig | 0.50 | 8.8 | 0.00 | Mar 11, 2025 | Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue. | ||
| CVE-2024-23646 | Hig | 0.50 | 8.8 | 0.01 | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user… | ||
| CVE-2024-23648 | Hig | 0.50 | 8.8 | 0.01 | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL sent contains a unique token, valid during 24 hours,… | ||
| CVE-2023-47637 | Hig | 0.50 | 8.8 | 0.01 | Nov 15, 2023 | Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One… | ||
| CVE-2023-2984 | Hig | 0.50 | 8.8 | 0.01 | May 30, 2023 | Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | ||
| CVE-2023-2983 | Hig | 0.50 | 8.8 | 0.01 | May 30, 2023 | Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23. | ||
| CVE-2023-30850 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. | ||
| CVE-2023-30849 | Hig | 0.50 | 8.8 | 0.01 | Apr 27, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. |
- risk 0.59cvss 8.8epss 0.69
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…
- risk 0.57cvss 8.8epss 0.00
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without…
- risk 0.57cvss 8.8epss 0.01
An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.
- risk 0.57cvss 9.8epss 0.02
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
- risk 0.57cvss 9.8epss 0.01
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
- risk 0.55cvss 8.8epss 0.63
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
- risk 0.53cvss 8.8epss 0.03
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.
- risk 0.52cvss 9.0epss 0.01
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.50cvss 8.8epss 0.00
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a…
- risk 0.50cvss 8.7epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through…
- risk 0.50cvss 8.8epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL…
- risk 0.50cvss 8.8epss 0.00
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.
- risk 0.50cvss 8.8epss 0.01
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user…
- risk 0.50cvss 8.8epss 0.01
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL sent contains a unique token, valid during 24 hours,…
- risk 0.50cvss 8.8epss 0.01
Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One…
- risk 0.50cvss 8.8epss 0.01
Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.
- risk 0.50cvss 8.8epss 0.01
Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.
- risk 0.50cvss 8.8epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.