Pimcore

Pimcore

139 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 12.08.2026 17:06:19
  • Zuletzt bearbeitet 12.08.2026 18:17:29

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolate...

  • EPSS 0.31%
  • Veröffentlicht 17.07.2026 19:12:50
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Co...

  • EPSS 0.29%
  • Veröffentlicht 17.07.2026 19:10:10
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration th...

  • EPSS 0.43%
  • Veröffentlicht 17.07.2026 19:08:38
  • Zuletzt bearbeitet 23.07.2026 16:04:11

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Contro...

  • EPSS 0.19%
  • Veröffentlicht 17.07.2026 18:52:44
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the word_export feature permission and dir...

  • EPSS 0.57%
  • Veröffentlicht 17.07.2026 18:50:19
  • Zuletzt bearbeitet 22.07.2026 20:50:36

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, includ...

  • EPSS 0.35%
  • Veröffentlicht 09.07.2026 21:02:02
  • Zuletzt bearbeitet 10.07.2026 15:52:52

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker...

  • EPSS 0.25%
  • Veröffentlicht 09.07.2026 20:57:53
  • Zuletzt bearbeitet 10.07.2026 15:52:52

Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the DateFilter colu...

  • EPSS 0.2%
  • Veröffentlicht 09.07.2026 20:53:36
  • Zuletzt bearbeitet 10.07.2026 21:16:55

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by the objects pe...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.04.2026 20:16:01
  • Zuletzt bearbeitet 18.05.2026 18:01:15

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.