Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-18985 Pimcore before 6.2.2 lacks brute force protection for the 2FA token. Pimcore 6.2.2+ Fix from $2,3002019-11-15 MEDIUM 6.1 CVE-2019-18982 bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of t… Pimcore 6.3.0+ Fix from $1,6002019-11-15 MEDIUM 6.1 CVE-2019-18656 Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HT… Pimcore Patch available Fix from $1,6002019-10-31 HIGH 8.8 CVE-2019-16317 In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because… Pimcore 5.7.1+ Fix from $1,9502019-09-14 HIGH 8.8 CVE-2019-16318 In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by … Pimcore 5.7.1+ Fix from $1,9502019-09-14 HIGH 8.8 CVE-2019-10867EPSS 69% An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will … Pimcore 5.7.1+ Fix from $1,9502019-04-04 MEDIUM 5.4 CVE-2018-14059 Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Documen… Pimcore after 5.2.3 Fix from $1,6002018-08-24 HIGH 8.8 CVE-2018-14057 Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke… Pimcore 5.3.0+ Fix from $1,9502018-08-17 MEDIUM 6.5 CVE-2018-14058EPSS 29% Pimcore before 5.3.0 allows SQL Injection via the REST web service API. Pimcore 5.3.0+ Fix from $1,6002018-08-17 HIGH 7.5 CVE-2015-4426 SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/… Pimcore Patch available Fix from $1,9502015-08-18 HIGH 7.5 CVE-2014-2921EPSS 7% The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an obje… Pimcore Patch available Fix from $1,9502014-04-21 MEDIUM 6.4 CVE-2014-2922 The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an obje… Pimcore No fix yet Fix from $1,6002014-04-21