CVE-2026-55416
- EPSS 0.61%
- Veröffentlicht 14.09.2026 16:52:28
- Zuletzt bearbeitet 16.09.2026 13:42:48
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of ...
CVE-2026-55072
- EPSS 0.37%
- Veröffentlicht 14.09.2026 16:50:27
- Zuletzt bearbeitet 16.09.2026 13:42:48
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/Class...
CVE-2026-55634
- EPSS 0.45%
- Veröffentlicht 28.08.2026 19:16:20
- Zuletzt bearbeitet 09.09.2026 21:09:13
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name ...
CVE-2026-55220
- EPSS 0.5%
- Veröffentlicht 28.08.2026 19:12:43
- Zuletzt bearbeitet 09.09.2026 21:09:13
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspotimage.php pas...
CVE-2026-44741
- EPSS 0.35%
- Veröffentlicht 12.08.2026 17:06:19
- Zuletzt bearbeitet 16.09.2026 13:42:43
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolate...
CVE-2026-45704
- EPSS 0.31%
- Veröffentlicht 17.07.2026 19:12:50
- Zuletzt bearbeitet 22.07.2026 20:50:36
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Co...
CVE-2026-44739
- EPSS 0.29%
- Veröffentlicht 17.07.2026 19:10:10
- Zuletzt bearbeitet 22.07.2026 20:50:36
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration th...
CVE-2026-45260
- EPSS 0.43%
- Veröffentlicht 17.07.2026 19:08:38
- Zuletzt bearbeitet 23.07.2026 16:04:11
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Contro...
CVE-2026-45703
- EPSS 0.19%
- Veröffentlicht 17.07.2026 18:52:44
- Zuletzt bearbeitet 22.07.2026 20:50:36
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and dir...
- EPSS 0.57%
- Veröffentlicht 17.07.2026 18:50:19
- Zuletzt bearbeitet 22.07.2026 20:50:36
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, includ...