📦 Pimcore

by Pimcore

🔍 What is Pimcore?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-23493

HIGH CVSS 8.6 Jan 15, 2026

Pimcore versions before 12.3.1 and 11.5.14 store sensitive information like database passwords and session cookies in the http_error_log file, which can be accessed through the Pimcore backend. This a...

CVE-2026-23492

HIGH CVSS 8.8 Jan 14, 2026

This CVE describes a blind SQL injection vulnerability in Pimcore's Admin Search Find API that affects authenticated users. Attackers can infer database information through blind injection techniques ...

CVE-2025-27617

HIGH CVSS 8.8 Mar 11, 2025

This SQL injection vulnerability in Pimcore allows authenticated users to craft malicious filter strings that can execute arbitrary SQL commands. The vulnerability affects all Pimcore installations pr...

CVE-2023-47637

HIGH CVSS 8.8 Nov 15, 2023

This is a SQL injection vulnerability in Pimcore's admin interface that allows authenticated backend users with basic permissions to execute arbitrary SQL statements. Attackers can alter data, escalat...

CVE-2023-3820

HIGH CVSS 7.2 Jul 21, 2023

CVE-2023-3820 is an SQL injection vulnerability in Pimcore's data object grid feature that allows attackers to execute arbitrary SQL commands. This affects all Pimcore installations prior to version 1...

CVE-2023-3673

HIGH CVSS 7.2 Jul 14, 2023

This CVE describes a SQL injection vulnerability in Pimcore CMS versions prior to 10.5.24. Attackers can inject malicious SQL queries through user-controlled input, potentially accessing or manipulati...

CVE-2023-2983

HIGH CVSS 8.8 May 30, 2023

This vulnerability in Pimcore allows attackers to perform unsafe actions due to improperly defined privileges, potentially leading to privilege escalation or unauthorized operations. It affects all us...

CVE-2023-30850

HIGH CVSS 8.8 Apr 27, 2023

CVE-2023-30850 is a SQL injection vulnerability in Pimcore's admin translations API that allows authenticated attackers to execute arbitrary SQL commands. This affects Pimcore installations before ver...

CVE-2023-30848

HIGH CVSS 8.8 Apr 27, 2023

CVE-2023-30848 is a SQL injection vulnerability in Pimcore's admin search find API that allows attackers to execute arbitrary SQL commands. This affects all Pimcore installations prior to version 10.5...

CVE-2023-2338

HIGH CVSS 8.8 Apr 27, 2023

CVE-2023-2338 is an SQL injection vulnerability in Pimcore's data management system that allows attackers to execute arbitrary SQL commands through crafted input. This affects all Pimcore installation...

CVE-2023-1578

HIGH CVSS 8.8 Mar 22, 2023

This CVE describes an SQL injection vulnerability in Pimcore, an open-source content management platform. Attackers can inject malicious SQL queries through user inputs, potentially accessing or manip...

CVE-2023-28108

HIGH CVSS 7.9 Mar 16, 2023

This CVE describes an SQL injection vulnerability in Pimcore's UUID DAO model where improper quoting allows SQL injection if developers use affected methods with untrusted input. It affects Pimcore in...

CVE-2023-25240

HIGH CVSS 8.8 Feb 13, 2023

CVE-2023-25240 is an improper SameSite attribute vulnerability in pimCore v10.5.15 that allows attackers to bypass SameSite cookie restrictions, potentially leading to Cross-Site Request Forgery (CSRF...

CVE-2023-23937

HIGH CVSS 8.2 Feb 3, 2023

This vulnerability allows authenticated users to bypass file upload validation in Pimcore by adding a fake GIF signature to malicious files. Attackers can upload HTML files containing JavaScript that ...

CVE-2022-31092

HIGH CVSS 7.5 Jun 27, 2022

CVE-2022-31092 is an SQL injection vulnerability in Pimcore's listing classes where improper quoting of order/group columns allows SQL injection when developers use these methods with untrusted input....

CVE-2022-0565

HIGH CVSS 7.6 Feb 14, 2022

This is a cross-site scripting (XSS) vulnerability in Pimcore's web interface that allows attackers to inject malicious scripts into web pages viewed by other users. It affects all Pimcore installatio...

CVE-2022-0263

HIGH CVSS 7.8 Jan 18, 2022

This vulnerability allows attackers to upload malicious files to Pimcore systems due to insufficient file type validation. It affects all Pimcore installations prior to version 10.2.7. Attackers could...

CVE-2021-39170

HIGH CVSS 8.0 Sep 1, 2021

CVE-2021-39170 is a stored cross-site scripting (XSS) vulnerability in Pimcore that allows authenticated users to inject malicious scripts into asset metadata fields. When other users view assets cont...

CVE-2021-23405

HIGH CVSS 8.3 Jul 9, 2021

This is a SQL injection vulnerability in Pimcore's ClassificationstoreController that allows attackers to execute arbitrary SQL commands. It affects Pimcore installations before version 10.0.7 where t...

CVE-2026-27461

MEDIUM CVSS 4.9 Feb 24, 2026

This SQL injection vulnerability in Pimcore allows authenticated admin users to extract the entire database, including password hashes of other admin accounts. It affects Pimcore versions up to 11.5.1...

CVE-2026-23494

MEDIUM CVSS 4.3 Jan 15, 2026

This CVE describes an authorization bypass vulnerability in Pimcore's API endpoint for static routes. Authenticated backend users without proper permissions can access sensitive route configurations, ...

CVE-2024-11956

MEDIUM CVSS 4.7 Jan 28, 2025

This critical SQL injection vulnerability in Pimcore Customer Data Framework allows remote attackers to execute arbitrary SQL commands via the filterDefinition/filter parameter in the customer managem...

CVE-2023-1702

MEDIUM CVSS 5.4 Mar 29, 2023

This CVE describes a cross-site scripting (XSS) vulnerability in Pimcore, an open-source content management platform. Attackers can inject malicious scripts into web pages viewed by other users, poten...

CVE-2023-1704

MEDIUM CVSS 5.4 Mar 29, 2023

This stored cross-site scripting (XSS) vulnerability in Pimcore allows attackers to inject malicious scripts into web pages that are then executed when other users view those pages. It affects all Pim...

CVE-2023-28438

MEDIUM CVSS 6.2 Mar 22, 2023

This CVE-2023-28438 is a SQL injection vulnerability in Pimcore's reporting feature that allows authenticated users with 'report' permission to execute arbitrary SQL queries via CSRF attacks. Attacker...