CVE-2026-23492
- EPSS 0.44%
- Veröffentlicht 14.01.2026 18:21:55
- Zuletzt bearbeitet 20.01.2026 21:45:58
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 atte...
CVE-2025-27617
- EPSS 0.48%
- Veröffentlicht 11.03.2025 15:35:51
- Zuletzt bearbeitet 04.11.2025 21:07:40
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.
CVE-2024-11954
- EPSS 1.06%
- Veröffentlicht 28.01.2025 14:15:29
- Zuletzt bearbeitet 04.11.2025 17:40:09
A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remot...
CVE-2024-11956
- EPSS 0.84%
- Veröffentlicht 28.01.2025 14:15:29
- Zuletzt bearbeitet 04.11.2025 17:36:29
A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of ...
CVE-2023-2332
- EPSS 0.36%
- Veröffentlicht 15.11.2024 11:15:08
- Zuletzt bearbeitet 19.11.2024 15:55:24
A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the Date Range section, allowing an attacker to inject mali...
CVE-2024-49370
- EPSS 0.52%
- Veröffentlicht 23.10.2024 15:15:31
- Zuletzt bearbeitet 06.11.2024 22:31:30
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to...
CVE-2024-32871
- EPSS 0.76%
- Veröffentlicht 04.06.2024 15:15:45
- Zuletzt bearbeitet 21.11.2024 09:15:54
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create file...
CVE-2024-29197
- EPSS 0.71%
- Veröffentlicht 26.03.2024 15:15:49
- Zuletzt bearbeitet 05.11.2025 22:18:50
Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a lo...
CVE-2023-49076
- EPSS 0.26%
- Veröffentlicht 30.11.2023 06:15:46
- Zuletzt bearbeitet 21.11.2024 08:32:46
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patche...
CVE-2023-47637
- EPSS 1.22%
- Veröffentlicht 15.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:34
Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterCondition()` on fields of classes to be filtered for, passing input from the request, and later executes the...