Pimcore

Pimcore

130 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.04.2026 20:16:01
  • Zuletzt bearbeitet 18.05.2026 18:01:15

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

  • EPSS 0.35%
  • Veröffentlicht 27.04.2026 19:15:04
  • Zuletzt bearbeitet 05.05.2026 18:16:03

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.02.2026 02:50:48
  • Zuletzt bearbeitet 25.02.2026 19:11:17

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded and the value field is concatenated directly into RL...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 20.01.2026 21:47:25

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, s...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 30.01.2026 19:49:56

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 15.01.2026 16:47:07
  • Zuletzt bearbeitet 30.01.2026 19:51:59

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configu...

  • EPSS 0.39%
  • Veröffentlicht 15.01.2026 16:38:23
  • Zuletzt bearbeitet 20.01.2026 21:48:53

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and o...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 14.01.2026 18:21:55
  • Zuletzt bearbeitet 20.01.2026 21:45:58

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 atte...

  • EPSS 0.45%
  • Veröffentlicht 11.03.2025 15:35:51
  • Zuletzt bearbeitet 04.11.2025 21:07:40

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.

Exploit
  • EPSS 0.99%
  • Veröffentlicht 28.01.2025 14:15:29
  • Zuletzt bearbeitet 04.11.2025 17:40:09

A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remot...