VYPR
Vendor

Pimcore

Products
10
CVEs
168
Across products
187
Status
Private

Products

10

Recent CVEs

168
View all 168 CVEs →
  • CVE-2019-10867HigApr 4, 2019
    risk 0.59cvss 8.8epss 0.69

    An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…

  • CVE-2026-72562HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without…

  • CVE-2023-25240HigFeb 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.

  • CVE-2022-39365CriOct 27, 2022
    risk 0.57cvss 9.8epss 0.02

    Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…

  • CVE-2019-18985CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks brute force protection for the 2FA token.

  • CVE-2019-18981CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.

  • CVE-2023-1578HigMar 22, 2023
    risk 0.55cvss 8.8epss 0.63

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

  • CVE-2018-14057HigAug 17, 2018
    risk 0.53cvss 8.8epss 0.03

    Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

  • CVE-2021-4139CriDec 21, 2021
    risk 0.52cvss 9.0epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2026-44741HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a…

  • CVE-2026-44739HigJul 17, 2026
    risk 0.50cvss 8.7epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through…

  • CVE-2026-23492HigJan 14, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL…

  • CVE-2025-27617HigMar 11, 2025
    risk 0.50cvss 8.8epss 0.00

    Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.

  • CVE-2024-23646HigJan 24, 2024
    risk 0.50cvss 8.8epss 0.01

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user…

  • CVE-2024-23648HigJan 24, 2024
    risk 0.50cvss 8.8epss 0.01

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL sent contains a unique token, valid during 24 hours,…

  • CVE-2023-47637HigNov 15, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the returned SQL. One…

  • CVE-2023-2984HigMay 30, 2023
    risk 0.50cvss 8.8epss 0.01

    Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

  • CVE-2023-2983HigMay 30, 2023
    risk 0.50cvss 8.8epss 0.01

    Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.

  • CVE-2023-30850HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.

  • CVE-2023-30849HigApr 27, 2023
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually.