Vendor CVEs
Pimcore
All CVEs
168 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45704 | Hig | 0.39 | — | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC… | ||
| CVE-2026-5394 | Hig | 0.39 | — | 0.00 | Apr 27, 2026 | An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3. | ||
| CVE-2021-23340 | Hig | 0.39 | 7.1 | 0.01 | Feb 18, 2021 | This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this… | ||
| CVE-2026-55072 | hig | 0.38 | — | — | Aug 13, 2026 | ### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw… | ||
| CVE-2018-14059 | Med | 0.38 | 5.4 | 0.03 | Aug 24, 2018 | Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions. | ||
| CVE-2026-45703 | Med | 0.35 | 6.4 | 0.00 | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves… | ||
| CVE-2026-5362 | Med | 0.35 | 5.4 | 0.00 | Apr 27, 2026 | An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3. | ||
| CVE-2024-24822 | Med | 0.35 | 6.5 | 0.01 | Feb 7, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually. | ||
| CVE-2024-21667 | Med | 0.35 | 6.5 | 0.01 | Jan 11, 2024 | pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure.… | ||
| CVE-2024-21666 | Med | 0.35 | 6.5 | 0.01 | Jan 11, 2024 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions… | ||
| CVE-2023-5192 | Med | 0.35 | 6.5 | 0.01 | Sep 27, 2023 | Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0. | ||
| CVE-2023-3819 | Med | 0.35 | 6.5 | 0.01 | Jul 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-3574 | Med | 0.35 | 6.5 | 0.01 | Jul 10, 2023 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | ||
| CVE-2023-30855 | Med | 0.35 | 6.5 | 0.01 | May 8, 2023 | Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.… | ||
| CVE-2023-2336 | Med | 0.35 | 6.5 | 0.01 | Apr 27, 2023 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2022-0665 | Med | 0.35 | 6.5 | 0.02 | Feb 22, 2022 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. | ||
| CVE-2024-41109 | Med | 0.34 | 6.3 | 0.00 | Jul 30, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their… | ||
| CVE-2023-38708 | Med | 0.34 | 6.3 | 0.01 | Aug 4, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by… | ||
| CVE-2023-46722 | Med | 0.33 | 6.1 | 0.01 | Oct 31, 2023 | The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other… | ||
| CVE-2023-3822 | Med | 0.33 | 6.1 | 0.01 | Jul 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-2341 | Med | 0.33 | 6.1 | 0.01 | Apr 27, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-28850 | Med | 0.33 | 6.1 | 0.01 | Apr 3, 2023 | Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect… | ||
| CVE-2023-28438 | Med | 0.33 | 6.2 | 0.01 | Mar 22, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject… | ||
| CVE-2023-28429 | Med | 0.33 | 6.1 | 0.01 | Mar 20, 2023 | Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through… | ||
| CVE-2023-28106 | Med | 0.33 | 6.1 | 0.01 | Mar 16, 2023 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch… | ||
| CVE-2022-0832 | Med | 0.33 | 5.4 | 0.67 | Mar 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. | ||
| CVE-2022-0262 | Med | 0.33 | 6.1 | 0.02 | Jan 18, 2022 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7. | ||
| CVE-2021-4084 | Med | 0.33 | 6.1 | 0.02 | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4081 | Med | 0.33 | 6.1 | 0.01 | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2019-18982 | Med | 0.33 | 6.1 | 0.01 | Nov 15, 2019 | bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header. | ||
| CVE-2019-18656 | Med | 0.33 | 6.1 | 0.01 | Oct 31, 2019 | Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements. | ||
| CVE-2024-49370 | Med | 0.32 | 4.9 | 0.01 | Oct 23, 2024 | Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine… | ||
| CVE-2026-23496 | Med | 0.28 | 5.4 | 0.00 | Jan 15, 2026 | Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing… | ||
| CVE-2023-47636 | Med | 0.28 | 5.3 | 0.01 | Nov 15, 2023 | The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using the load_file() (within a SQL Injection)… | ||
| CVE-2023-5873 | Med | 0.28 | 5.4 | 0.00 | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0. | ||
| CVE-2023-42817 | Med | 0.28 | 5.4 | 0.00 | Sep 25, 2023 | Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with… | ||
| CVE-2023-4453 | Med | 0.28 | 5.4 | 0.01 | Aug 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8. | ||
| CVE-2023-4145 | Med | 0.28 | 5.4 | 0.01 | Aug 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. | ||
| CVE-2023-3821 | Med | 0.28 | 5.4 | 0.01 | Jul 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4. | ||
| CVE-2023-2730 | Med | 0.28 | 5.4 | 0.00 | May 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. | ||
| CVE-2023-2615 | Med | 0.28 | 5.4 | 0.01 | May 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2614 | Med | 0.28 | 5.4 | 0.01 | May 10, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2616 | Med | 0.28 | 5.4 | 0.01 | May 10, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2361 | Med | 0.28 | 5.4 | 0.00 | Apr 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2343 | Med | 0.28 | 5.4 | 0.00 | Apr 27, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2342 | Med | 0.28 | 5.4 | 0.00 | Apr 27, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2340 | Med | 0.28 | 5.4 | 0.00 | Apr 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2339 | Med | 0.28 | 5.4 | 0.01 | Apr 27, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2328 | Med | 0.28 | 5.4 | 0.00 | Apr 27, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | ||
| CVE-2023-2327 | Med | 0.28 | 5.4 | 0.00 | Apr 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. |
- risk 0.39cvss —epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC…
- risk 0.39cvss —epss 0.00
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.
- risk 0.39cvss 7.1epss 0.01
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this…
- risk 0.38cvss —epss —
### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw…
- risk 0.38cvss 5.4epss 0.03
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
- risk 0.35cvss 6.4epss 0.00
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves…
- risk 0.35cvss 5.4epss 0.00
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.
- risk 0.35cvss 6.5epss 0.01
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually.
- risk 0.35cvss 6.5epss 0.01
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure.…
- risk 0.35cvss 6.5epss 0.01
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions…
- risk 0.35cvss 6.5epss 0.01
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.
- risk 0.35cvss 6.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.35cvss 6.5epss 0.01
Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.
- risk 0.35cvss 6.5epss 0.01
Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.…
- risk 0.35cvss 6.5epss 0.01
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.35cvss 6.5epss 0.02
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
- risk 0.34cvss 6.3epss 0.00
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their…
- risk 0.34cvss 6.3epss 0.01
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by…
- risk 0.33cvss 6.1epss 0.01
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other…
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.33cvss 6.1epss 0.01
Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect…
- risk 0.33cvss 6.2epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject…
- risk 0.33cvss 6.1epss 0.01
Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through…
- risk 0.33cvss 6.1epss 0.01
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch…
- risk 0.33cvss 5.4epss 0.67
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
- risk 0.33cvss 6.1epss 0.02
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.
- risk 0.33cvss 6.1epss 0.02
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.33cvss 6.1epss 0.01
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.33cvss 6.1epss 0.01
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
- risk 0.33cvss 6.1epss 0.01
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.
- risk 0.32cvss 4.9epss 0.01
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine…
- risk 0.28cvss 5.4epss 0.00
Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing…
- risk 0.28cvss 5.3epss 0.01
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using the load_file() (within a SQL Injection)…
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
- risk 0.28cvss 5.4epss 0.00
Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with…
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Page 2 of 4