Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-5362 An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script ex… Pimcore No fix yet Fix from $1,6002026-04-27 MEDIUM 6.5 CVE-2026-23494 Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side aut… Pimcore 11.5.14 / 12.3.1+ Fix from $1,6002026-01-15 MEDIUM 5.4 CVE-2026-23496 Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se… Web2print Tools 5.2.2 / 6.1.1+ Fix from $1,6002026-01-15 HIGH 8.8 CVE-2025-27617 Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cau… Pimcore 11.5.4+ Fix from $1,9502025-03-11 MEDIUM 5.3 CVE-2025-24980 pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to use… Admin Classic Bundle 1.7.4.1+ Fix from $1,6002025-02-07 HIGH 7.2 CVE-2024-11956 A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unkn… Pimcore 4.2.1+ Fix from $1,9502025-01-28 MEDIUM 6.5 CVE-2024-41109 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user e… Admin Classic Bundle 1.3.10 / 1.4.6+ Fix from $1,6002024-07-30 HIGH 7.5 CVE-2024-32871 Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. B… Pimcore 11.2.4+ Fix from $1,9502024-06-04 MEDIUM 6.5 CVE-2024-29197 Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished … Pimcore 11.1.6.1 / 11.2.2+ Fix from $1,6002024-03-26 CRITICAL 9.3 CVE-2024-25625 Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic… Admin Classic Bundle 1.3.4+ Fix from $2,3002024-02-19 CRITICAL 9.1 CVE-2024-24822 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags withou… Admin Classic Bundle 1.3.3+ Fix from $2,3002024-02-07 HIGH 8.8 CVE-2024-23646 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files o… Admin Classic Bundle 1.3.2+ Fix from $1,9502024-01-24 HIGH 8.8 CVE-2024-23648 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a pas… Admin Classic Bundle 1.2.3+ Fix from $1,9502024-01-24 MEDIUM 6.5 CVE-2024-21666 The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing auto… Customer Management Framework 4.0.6+ Fix from $1,6002024-01-11 MEDIUM 6.5 CVE-2024-21667 pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorize… Customer Management Framework 4.0.6+ Fix from $1,6002024-01-11 MEDIUM 6.5 CVE-2023-49076 Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, the… Pimcore 4.0.5+ Fix from $1,6002023-11-30 HIGH 7.2 CVE-2023-49075 The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two fa… Admin Classic Bundle 1.2.2+ Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-47637 Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterConditi… Pimcore 11.1.1+ Fix from $1,9502023-11-15 MEDIUM 5.3 CVE-2023-47636 The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to… Admin Classic Bundle 1.2.1+ Fix from $1,6002023-11-15 MEDIUM 6.1 CVE-2023-46722 The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to… Admin Classic Bundle 1.2.0+ Fix from $1,6002023-10-31 MEDIUM 5.4 CVE-2023-5873 Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0. Pimcore 11.1.0+ Fix from $1,6002023-10-31 HIGH 7.2 CVE-2023-5844 Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. Admin Classic Bundle after 1.1.4 Fix from $1,9502023-10-30 MEDIUM 6.5 CVE-2023-5192 Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0. Core 10.3.0+ Fix from $1,6002023-09-27 MEDIUM 5.4 CVE-2023-42817 Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by spri… Admin Classic Bundle 1.1.2+ Fix from $1,6002023-09-25 MEDIUM 5.4 CVE-2023-4453 Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8. Pimcore 10.6.8+ Fix from $1,6002023-08-21 HIGH 8.8 CVE-2023-38708 Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist… Pimcore 10.6.7+ Fix from $1,9502023-08-04 MEDIUM 5.4 CVE-2023-4145 Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. Customer Management Framework 3.4.2+ Fix from $1,6002023-08-03 HIGH 7.2 CVE-2023-3820 SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4. Pimcore 10.6.4+ Fix from $1,9502023-07-21 MEDIUM 6.5 CVE-2023-3819 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. Pimcore 10.6.4+ Fix from $1,6002023-07-21 MEDIUM 6.1 CVE-2023-3822 Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4. Pimcore 10.6.4+ Fix from $1,6002023-07-21