Pimcore Vulnerabilities

Comprehensive security vulnerability database for Pimcore products

Last updated: Aug 3, 2023
Total CVEs

3

Critical

0

With Exploits

2

Last 30 Days

0

Severity Distribution

Critical0
0%
High1
33%
Medium2
67%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2023-41455.4

This vulnerability allows an attacker to inject malicious scripts into the customer management framework, which can then be executed in the browsers of users who access the affected application. It requires the attacker to have the ability to input data into the system, making it particularly dangerous if user-generated content is not properly sanitized.

pimcorecustomer management framework
Exploit Available
over 2 years agoAug 3, 2023
CVE-2023-28814.9

This vulnerability allows an attacker to potentially access user passwords stored in a recoverable format within the customer management framework, which could lead to unauthorized account access. It affects versions prior to 3.3.10, meaning systems running older versions are at risk if they haven't been updated.

pimcorecustomer management framework
Exploit Available
almost 3 years agoMay 25, 2023
CVE-2021-318697.5

This vulnerability allows an attacker to manipulate database queries, potentially gaining unauthorized access to sensitive data or executing harmful commands. It affects versions 6.8.0 and earlier of the Pimcore AdminBundle, and users should upgrade to version 6.9.4 or later to protect against this issue.

pimcorepimcore
Theoretical
over 4 years agoAug 4, 2021

About Pimcore Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Pimcore products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.