Pimcore Security Vulnerabilities (CVEs)
Track 34 security vulnerabilities affecting Pimcore products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This SQL injection vulnerability in Pimcore allows authenticated admin users to extract the entire database, including password hashes of other admin ...
Feb 24, 2026Pimcore versions before 12.3.1 and 11.5.14 store sensitive information like database passwords and session cookies in the http_error_log file, which c...
Jan 15, 2026This CVE describes an authorization bypass vulnerability in Pimcore's API endpoint for static routes. Authenticated backend users without proper permi...
Jan 15, 2026This vulnerability allows authenticated backend users without proper permissions to access the complete list of Predefined Properties configurations i...
Jan 15, 2026This CVE describes an authorization bypass vulnerability in Pimcore Web2Print Tools Bundle. Authenticated backend users without proper permissions can...
Jan 15, 2026This CVE describes a blind SQL injection vulnerability in Pimcore's Admin Search Find API that affects authenticated users. Attackers can infer databa...
Jan 14, 2026This SQL injection vulnerability in Pimcore allows authenticated users to craft malicious filter strings that can execute arbitrary SQL commands. The ...
Mar 11, 2025This vulnerability in pimcore/admin-ui-classic-bundle allows attackers to enumerate valid user accounts via the 'Forgot password' function due to impr...
Feb 7, 2025This critical SQL injection vulnerability in Pimcore Customer Data Framework allows remote attackers to execute arbitrary SQL commands via the filterD...
Jan 28, 2025This vulnerability in Pimcore's Admin Classic Bundle exposes sensitive system information to authenticated users. By accessing the /admin/index/statis...
Jul 30, 2024This CVE describes a Host Header Injection vulnerability in Pimcore's Admin Classic Bundle that allows attackers to manipulate invitation email links....
Feb 19, 2024This vulnerability in Pimcore's Admin Classic Bundle allows attackers to perform account takeover by manipulating password reset emails. Attackers can...
Jan 24, 2024This vulnerability in Pimcore's Admin Classic Bundle disables two-factor authentication for non-admin security firewalls, allowing authenticated users...
Nov 28, 2023This is a SQL injection vulnerability in Pimcore's admin interface that allows authenticated backend users with basic permissions to execute arbitrary...
Nov 15, 2023This vulnerability allows unauthenticated attackers to change passwords for any user account in Pimcore's admin-ui-classic-bundle without verification...
Oct 30, 2023CVE-2023-3820 is an SQL injection vulnerability in Pimcore's data object grid feature that allows attackers to execute arbitrary SQL commands. This af...
Jul 21, 2023This CVE describes a SQL injection vulnerability in Pimcore CMS versions prior to 10.5.24. Attackers can inject malicious SQL queries through user-con...
Jul 14, 2023This vulnerability in Pimcore allows attackers to perform unsafe actions due to improperly defined privileges, potentially leading to privilege escala...
May 30, 2023This vulnerability allows CSV formula injection attacks in Pimcore Customer Data Framework. Attackers can embed malicious formulas in CSV files that e...
May 10, 2023CVE-2023-30850 is a SQL injection vulnerability in Pimcore's admin translations API that allows authenticated attackers to execute arbitrary SQL comma...
Apr 27, 2023CVE-2023-30848 is a SQL injection vulnerability in Pimcore's admin search find API that allows attackers to execute arbitrary SQL commands. This affec...
Apr 27, 2023CVE-2023-2338 is an SQL injection vulnerability in Pimcore's data management system that allows attackers to execute arbitrary SQL commands through cr...
Apr 27, 2023This CVE describes a cross-site scripting (XSS) vulnerability in Pimcore, an open-source content management platform. Attackers can inject malicious s...
Mar 29, 2023This stored cross-site scripting (XSS) vulnerability in Pimcore allows attackers to inject malicious scripts into web pages that are then executed whe...
Mar 29, 2023This CVE-2023-28438 is a SQL injection vulnerability in Pimcore's reporting feature that allows authenticated users with 'report' permission to execut...
Mar 22, 2023This CVE describes an SQL injection vulnerability in Pimcore, an open-source content management platform. Attackers can inject malicious SQL queries t...
Mar 22, 2023This CVE describes an SQL injection vulnerability in Pimcore's UUID DAO model where improper quoting allows SQL injection if developers use affected m...
Mar 16, 2023CVE-2023-25240 is an improper SameSite attribute vulnerability in pimCore v10.5.15 that allows attackers to bypass SameSite cookie restrictions, poten...
Feb 13, 2023This vulnerability allows authenticated users to bypass file upload validation in Pimcore by adding a fake GIF signature to malicious files. Attackers...
Feb 3, 2023CVE-2022-31092 is an SQL injection vulnerability in Pimcore's listing classes where improper quoting of order/group columns allows SQL injection when ...
Jun 27, 2022This is a cross-site scripting (XSS) vulnerability in Pimcore's web interface that allows attackers to inject malicious scripts into web pages viewed ...
Feb 14, 2022This vulnerability allows attackers to upload malicious files to Pimcore systems due to insufficient file type validation. It affects all Pimcore inst...
Jan 18, 2022CVE-2021-39170 is a stored cross-site scripting (XSS) vulnerability in Pimcore that allows authenticated users to inject malicious scripts into asset ...
Sep 1, 2021This is a SQL injection vulnerability in Pimcore's ClassificationstoreController that allows attackers to execute arbitrary SQL commands. It affects P...
Jul 9, 2021Why Monitor Pimcore Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 34+ known vulnerabilities affecting Pimcore products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Pimcore packages in under 60 seconds. No agents required - completely agentless scanning that works across Pimcore deployments.
Free vulnerability database: Access detailed information about every Pimcore CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Pimcore CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions