Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pimcore MEDIUM 5.4
CVE-2026-5362

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script ex…

No fix yet
Fix from $1,600 2026-04-27
Pimcore MEDIUM 6.5
CVE-2026-23494

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side aut…

Fix: 11.5.14 / 12.3.1+
Fix from $1,600 2026-01-15
Web2print Tools MEDIUM 5.4
CVE-2026-23496

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper se…

Fix: 5.2.2 / 6.1.1+
Fix from $1,600 2026-01-15
Pimcore HIGH 8.8
CVE-2025-27617

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cau…

Fix: 11.5.4+
Fix from $1,950 2025-03-11
Admin Classic Bundle MEDIUM 5.3
CVE-2025-24980

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to use…

Fix: 1.7.4.1+
Fix from $1,600 2025-02-07
Pimcore HIGH 7.2
CVE-2024-11956

A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unkn…

Fix: 4.2.1+
Fix from $1,950 2025-01-28
Admin Classic Bundle MEDIUM 6.5
CVE-2024-41109

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user e…

Fix: 1.3.10 / 1.4.6+
Fix from $1,600 2024-07-30
Pimcore HIGH 7.5
CVE-2024-32871

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. B…

Fix: 11.2.4+
Fix from $1,950 2024-06-04
Pimcore MEDIUM 6.5
CVE-2024-29197

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished …

Fix: 11.1.6.1 / 11.2.2+
Fix from $1,600 2024-03-26
Admin Classic Bundle CRITICAL 9.3
CVE-2024-25625

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic…

Fix: 1.3.4+
Fix from $2,300 2024-02-19
Admin Classic Bundle CRITICAL 9.1
CVE-2024-24822

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags withou…

Fix: 1.3.3+
Fix from $2,300 2024-02-07
Admin Classic Bundle HIGH 8.8
CVE-2024-23646

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files o…

Fix: 1.3.2+
Fix from $1,950 2024-01-24
Admin Classic Bundle HIGH 8.8
CVE-2024-23648

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a pas…

Fix: 1.2.3+
Fix from $1,950 2024-01-24
Customer Management Framework MEDIUM 6.5
CVE-2024-21666

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing auto…

Fix: 4.0.6+
Fix from $1,600 2024-01-11
Customer Management Framework MEDIUM 6.5
CVE-2024-21667

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorize…

Fix: 4.0.6+
Fix from $1,600 2024-01-11
Pimcore MEDIUM 6.5
CVE-2023-49076

Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, the…

Fix: 4.0.5+
Fix from $1,600 2023-11-30
Admin Classic Bundle HIGH 7.2
CVE-2023-49075

The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two fa…

Fix: 1.2.2+
Fix from $1,950 2023-11-28
Pimcore HIGH 8.8
CVE-2023-47637

Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterConditi…

Fix: 11.1.1+
Fix from $1,950 2023-11-15
Admin Classic Bundle MEDIUM 5.3
CVE-2023-47636

The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to…

Fix: 1.2.1+
Fix from $1,600 2023-11-15
Admin Classic Bundle MEDIUM 6.1
CVE-2023-46722

The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to…

Fix: 1.2.0+
Fix from $1,600 2023-10-31
Pimcore MEDIUM 5.4
CVE-2023-5873

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

Fix: 11.1.0+
Fix from $1,600 2023-10-31
Admin Classic Bundle HIGH 7.2
CVE-2023-5844

Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.

Fix: after 1.1.4
Fix from $1,950 2023-10-30
Core MEDIUM 6.5
CVE-2023-5192

Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.

Fix: 10.3.0+
Fix from $1,600 2023-09-27
Admin Classic Bundle MEDIUM 5.4
CVE-2023-42817

Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by spri…

Fix: 1.1.2+
Fix from $1,600 2023-09-25
Pimcore MEDIUM 5.4
CVE-2023-4453

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.

Fix: 10.6.8+
Fix from $1,600 2023-08-21
Pimcore HIGH 8.8
CVE-2023-38708

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist…

Fix: 10.6.7+
Fix from $1,950 2023-08-04
Customer Management Framework MEDIUM 5.4
CVE-2023-4145

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

Fix: 3.4.2+
Fix from $1,600 2023-08-03
Pimcore HIGH 7.2
CVE-2023-3820

SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.

Fix: 10.6.4+
Fix from $1,950 2023-07-21
Pimcore MEDIUM 6.5
CVE-2023-3819

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

Fix: 10.6.4+
Fix from $1,600 2023-07-21
Pimcore MEDIUM 6.1
CVE-2023-3822

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

Fix: 10.6.4+
Fix from $1,600 2023-07-21