Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2019-18985
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
Pimcore
6.2.2+
MEDIUM 6.1
CVE-2019-18982
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of t…
Pimcore
6.3.0+
MEDIUM 6.1
CVE-2019-18656
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HT…
Pimcore
Patch available
HIGH 8.8
CVE-2019-16317
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because…
Pimcore
5.7.1+
HIGH 8.8
CVE-2019-16318
In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by …
Pimcore
5.7.1+
HIGH 8.8
CVE-2019-10867EPSS 69%
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will …
Pimcore
5.7.1+
MEDIUM 5.4
CVE-2018-14059
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Documen…
Pimcore
after 5.2.3
HIGH 8.8
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-toke…
Pimcore
5.3.0+
MEDIUM 6.5
CVE-2018-14058EPSS 29%
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
Pimcore
5.3.0+
HIGH 7.5
CVE-2015-4426
SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/…
Pimcore
Patch available
HIGH 7.5
CVE-2014-2921EPSS 7%
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an obje…
Pimcore
Patch available
MEDIUM 6.4
CVE-2014-2922
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an obje…
Pimcore
No fix yet