Pimcore

Pimcore

143 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 09.07.2026 21:02:02
  • Zuletzt bearbeitet 10.07.2026 15:52:52

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker...

  • EPSS 0.25%
  • Veröffentlicht 09.07.2026 20:57:53
  • Zuletzt bearbeitet 10.07.2026 15:52:52

Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the DateFilter colu...

  • EPSS 0.2%
  • Veröffentlicht 09.07.2026 20:53:36
  • Zuletzt bearbeitet 10.07.2026 21:16:55

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by the objects pe...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.04.2026 20:16:01
  • Zuletzt bearbeitet 18.05.2026 18:01:15

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

  • EPSS 0.35%
  • Veröffentlicht 27.04.2026 19:15:04
  • Zuletzt bearbeitet 05.05.2026 18:16:03

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.02.2026 02:50:48
  • Zuletzt bearbeitet 25.02.2026 19:11:17

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded and the value field is concatenated directly into RL...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 20.01.2026 21:47:25

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, s...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.01.2026 17:16:08
  • Zuletzt bearbeitet 30.01.2026 19:49:56

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 15.01.2026 16:47:07
  • Zuletzt bearbeitet 30.01.2026 19:51:59

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configu...

  • EPSS 0.4%
  • Veröffentlicht 15.01.2026 16:38:23
  • Zuletzt bearbeitet 20.01.2026 21:48:53

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and o...