Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pimcore CRITICAL 9.8
CVE-2019-18985

Pimcore before 6.2.2 lacks brute force protection for the 2FA token.

Fix: 6.2.2+
Fix from $2,300 2019-11-15
Pimcore MEDIUM 6.1
CVE-2019-18982

bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of t…

Fix: 6.3.0+
Fix from $1,600 2019-11-15
Pimcore MEDIUM 6.1
CVE-2019-18656

Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HT…

Patch available
Fix from $1,600 2019-10-31
Pimcore HIGH 8.8
CVE-2019-16317

In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because…

Fix: 5.7.1+
Fix from $1,950 2019-09-14
Pimcore HIGH 8.8
CVE-2019-16318

In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by …

Fix: 5.7.1+
Fix from $1,950 2019-09-14
Pimcore HIGH 8.8
CVE-2019-10867EPSS 69%

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will …

Fix: 5.7.1+
Fix from $1,950 2019-04-04
Pimcore MEDIUM 5.4
CVE-2018-14059

Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Documen…

Fix: after 5.2.3
Fix from $1,600 2018-08-24
Pimcore HIGH 8.8
CVE-2018-14057

Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke…

Fix: 5.3.0+
Fix from $1,950 2018-08-17
Pimcore MEDIUM 6.5
CVE-2018-14058EPSS 29%

Pimcore before 5.3.0 allows SQL Injection via the REST web service API.

Fix: 5.3.0+
Fix from $1,600 2018-08-17
Pimcore HIGH 7.5
CVE-2015-4426

SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/…

Patch available
Fix from $1,950 2015-08-18
Pimcore HIGH 7.5
CVE-2014-2921EPSS 7%

The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an obje…

Patch available
Fix from $1,950 2014-04-21
Pimcore MEDIUM 6.4
CVE-2014-2922

The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an obje…

No fix yet
Fix from $1,600 2014-04-21