VYPR

Vendor CVEs

Pimcore

All CVEs

137 total · sorted by risk
  • CVE-2022-1339Apr 13, 2022
    risk 0.00cvss epss 0.05

    SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

  • CVE-2022-1219Apr 8, 2022
    risk 0.00cvss epss 0.01

    SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

  • CVE-2022-0705Mar 16, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

  • CVE-2022-0704Mar 16, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

  • CVE-2022-0911Mar 16, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

  • CVE-2022-0893Mar 15, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

  • CVE-2022-0894Mar 15, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

  • CVE-2022-0832Mar 4, 2022
    risk 0.00cvss epss 0.67

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

  • CVE-2022-0831Mar 4, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

  • CVE-2022-0665Feb 22, 2022
    risk 0.00cvss epss 0.01

    Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.

  • CVE-2022-0565Feb 12, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.

  • CVE-2022-0510Feb 8, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.

  • CVE-2022-0509Feb 8, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

  • CVE-2022-0348Jan 27, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

  • CVE-2022-0251Jan 26, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.

  • CVE-2022-0285Jan 20, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

  • CVE-2022-0263Jan 18, 2022
    risk 0.00cvss epss 0.01

    Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2022-0262Jan 18, 2022
    risk 0.00cvss epss 0.02

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2021-4146Jan 18, 2022
    risk 0.00cvss epss 0.01

    Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.

  • CVE-2022-0260Jan 18, 2022
    risk 0.00cvss epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.

  • CVE-2022-0257Jan 17, 2022
    risk 0.00cvss epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2022-0258Jan 17, 2022
    risk 0.00cvss epss 0.02

    pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

  • CVE-2022-0256Jan 17, 2022
    risk 0.00cvss epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4139Dec 21, 2021
    risk 0.00cvss epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4084Dec 10, 2021
    risk 0.00cvss epss 0.02

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4081Dec 10, 2021
    risk 0.00cvss epss 0.01

    pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-4082Dec 10, 2021
    risk 0.00cvss epss 0.00

    pimcore is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-39189Sep 15, 2021
    risk 0.00cvss epss 0.01

    Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

  • CVE-2021-39170Sep 1, 2021
    risk 0.00cvss epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch…

  • CVE-2021-39166Sep 1, 2021
    risk 0.00cvss epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version…

  • CVE-2021-37702Aug 18, 2021
    risk 0.00cvss epss 0.01

    Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

  • CVE-2021-31869Aug 4, 2021
    risk 0.00cvss epss 0.01

    Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.

  • CVE-2021-31867Aug 4, 2021
    risk 0.00cvss epss 0.01

    Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.

  • CVE-2020-26246Dec 3, 2020
    risk 0.00cvss epss 0.01

    Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

  • CVE-2015-4426Aug 18, 2015
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy.

  • CVE-2015-4425Aug 18, 2015
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

  • CVE-2014-2921Apr 21, 2014
    risk 0.00cvss epss 0.07

    The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object injection attacks and execute…

Page 3 of 3