📦 Admin Classic Bundle

by Pimcore

🔍 What is Admin Classic Bundle?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-25625

HIGH CVSS 8.1 Feb 19, 2024

This CVE describes a Host Header Injection vulnerability in Pimcore's Admin Classic Bundle that allows attackers to manipulate invitation email links. By sending crafted HTTP requests with malicious h...

CVE-2024-23648

HIGH CVSS 8.8 Jan 24, 2024

This vulnerability in Pimcore's Admin Classic Bundle allows attackers to perform account takeover by manipulating password reset emails. Attackers can send password reset requests with a malicious Hos...

CVE-2023-49075

HIGH CVSS 8.4 Nov 28, 2023

This vulnerability in Pimcore's Admin Classic Bundle disables two-factor authentication for non-admin security firewalls, allowing authenticated users to bypass 2FA requirements. It affects systems us...

CVE-2023-5844

HIGH CVSS 7.2 Oct 30, 2023

This vulnerability allows unauthenticated attackers to change passwords for any user account in Pimcore's admin-ui-classic-bundle without verification. It affects all installations using versions prio...

CVE-2026-23495

MEDIUM CVSS 4.3 Jan 15, 2026

This vulnerability allows authenticated backend users without proper permissions to access the complete list of Predefined Properties configurations in Pimcore's Admin Classic Bundle. It affects organ...

CVE-2025-24980

MEDIUM CVSS 5.3 Feb 7, 2025

This vulnerability in pimcore/admin-ui-classic-bundle allows attackers to enumerate valid user accounts via the 'Forgot password' function due to improper error messages. Attackers can determine which...

CVE-2024-41109

MEDIUM CVSS 6.3 Jul 30, 2024

This vulnerability in Pimcore's Admin Classic Bundle exposes sensitive system information to authenticated users. By accessing the /admin/index/statistics endpoint, attackers can obtain details about ...