Pimcore

Pimcore

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 24.02.2026 02:50:48
  • Zuletzt bearbeitet 25.02.2026 19:11:17

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded and the value field is concatenated directly into RL...

Exploit
  • EPSS 0%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 20.01.2026 21:47:25

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, s...

Exploit
  • EPSS 0%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 30.01.2026 19:49:56

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel...

Exploit
  • EPSS 0%
  • Veröffentlicht 15.01.2026 16:47:07
  • Zuletzt bearbeitet 30.01.2026 19:51:59

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configu...

  • EPSS 0%
  • Veröffentlicht 15.01.2026 16:38:23
  • Zuletzt bearbeitet 20.01.2026 21:48:53

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and o...

Exploit
  • EPSS 0%
  • Veröffentlicht 14.01.2026 18:21:55
  • Zuletzt bearbeitet 20.01.2026 21:45:58

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 atte...

  • EPSS 0.51%
  • Veröffentlicht 11.03.2025 15:35:51
  • Zuletzt bearbeitet 04.11.2025 21:07:40

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 28.01.2025 14:15:29
  • Zuletzt bearbeitet 04.11.2025 17:40:09

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remot...

Exploit
  • EPSS 0%
  • Veröffentlicht 28.01.2025 14:15:29
  • Zuletzt bearbeitet 04.11.2025 17:36:29

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of ...

Exploit
  • EPSS 0%
  • Veröffentlicht 15.11.2024 11:15:08
  • Zuletzt bearbeitet 19.11.2024 15:55:24

A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the Date Range section, allowing an attacker to inject mali...