VYPR

Vendor CVEs

Pimcore

All CVEs

168 total · sorted by risk
  • CVE-2026-45704HigJul 17, 2026
    risk 0.39cvss epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportC…

  • CVE-2026-5394HigApr 27, 2026
    risk 0.39cvss epss 0.00

    An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

  • CVE-2021-23340HigFeb 18, 2021
    risk 0.39cvss 7.1epss 0.01

    This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomReportController.php). An authenticated user can reach this…

  • CVE-2026-55072higAug 13, 2026
    risk 0.38cvss epss

    ### Summary A missing end anchor (`$`) in the ClassDefinition UID validation regex allows an authenticated user with the `objects` permission to create a class with a malicious UID containing SQL. When a data object of that class is later loaded, Block.php concatenates the raw…

  • CVE-2018-14059MedAug 24, 2018
    risk 0.38cvss 5.4epss 0.03

    Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.

  • CVE-2026-45703MedJul 17, 2026
    risk 0.35cvss 6.4epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and directly resolves…

  • CVE-2026-5362MedApr 27, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

  • CVE-2024-24822MedFeb 7, 2024
    risk 0.35cvss 6.5epss 0.01

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually.

  • CVE-2024-21667MedJan 11, 2024
    risk 0.35cvss 6.5epss 0.01

    pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure.…

  • CVE-2024-21666MedJan 11, 2024
    risk 0.35cvss 6.5epss 0.01

    The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions…

  • CVE-2023-5192MedSep 27, 2023
    risk 0.35cvss 6.5epss 0.01

    Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.

  • CVE-2023-3819MedJul 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-3574MedJul 10, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.

  • CVE-2023-30855MedMay 8, 2023
    risk 0.35cvss 6.5epss 0.01

    Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files.…

  • CVE-2023-2336MedApr 27, 2023
    risk 0.35cvss 6.5epss 0.01

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2022-0665MedFeb 22, 2022
    risk 0.35cvss 6.5epss 0.02

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

  • CVE-2024-41109MedJul 30, 2024
    risk 0.34cvss 6.3epss 0.00

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their…

  • CVE-2023-38708MedAug 4, 2023
    risk 0.34cvss 6.3epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by…

  • CVE-2023-46722MedOct 31, 2023
    risk 0.33cvss 6.1epss 0.01

    The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other…

  • CVE-2023-3822MedJul 21, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-2341MedApr 27, 2023
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-28850MedApr 3, 2023
    risk 0.33cvss 6.1epss 0.01

    Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect…

  • CVE-2023-28438MedMar 22, 2023
    risk 0.33cvss 6.2epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject…

  • CVE-2023-28429MedMar 20, 2023
    risk 0.33cvss 6.1epss 0.01

    Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through…

  • CVE-2023-28106MedMar 16, 2023
    risk 0.33cvss 6.1epss 0.01

    Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch…

  • CVE-2022-0832MedMar 4, 2022
    risk 0.33cvss 5.4epss 0.67

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

  • CVE-2022-0262MedJan 18, 2022
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2021-4084MedDec 10, 2021
    risk 0.33cvss 6.1epss 0.02

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4081MedDec 10, 2021
    risk 0.33cvss 6.1epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2019-18982MedNov 15, 2019
    risk 0.33cvss 6.1epss 0.01

    bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.

  • CVE-2019-18656MedOct 31, 2019
    risk 0.33cvss 6.1epss 0.01

    Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.

  • CVE-2024-49370MedOct 23, 2024
    risk 0.32cvss 4.9epss 0.01

    Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine…

  • CVE-2026-23496MedJan 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing…

  • CVE-2023-47636MedNov 15, 2023
    risk 0.28cvss 5.3epss 0.01

    The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain vulnerabilities, such as using the load_file() (within a SQL Injection)…

  • CVE-2023-5873MedOct 31, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

  • CVE-2023-42817MedSep 25, 2023
    risk 0.28cvss 5.4epss 0.00

    Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by a user with…

  • CVE-2023-4453MedAug 21, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.

  • CVE-2023-4145MedAug 3, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

  • CVE-2023-3821MedJul 21, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4.

  • CVE-2023-2730MedMay 16, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

  • CVE-2023-2615MedMay 10, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2614MedMay 10, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2616MedMay 10, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2361MedApr 28, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2343MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2342MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2340MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2339MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2328MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

  • CVE-2023-2327MedApr 27, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.