Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

pimcore — Vulnerabilities & Security Advisories 133

Browse all 133 CVE security advisories affecting pimcore. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2022-0258 SQL Injection in pimcore/pimcore — pimcore/pimcoreCWE-89 8.8 -2022-01-17
CVE-2022-0256 Cross-site Scripting (XSS) - Stored in pimcore/pimcore — pimcore/pimcoreCWE-79 5.4 -2022-01-17
CVE-2021-4139 Cross-site Scripting (XSS) - Stored in pimcore/pimcore — pimcore/pimcoreCWE-79 5.4 -2021-12-21
CVE-2021-4084 Cross-site Scripting (XSS) - Stored in pimcore/pimcore — pimcore/pimcoreCWE-79 5.4 -2021-12-10
CVE-2021-4081 Cross-site Scripting (XSS) - Reflected in pimcore/pimcore — pimcore/pimcoreCWE-79 5.4 -2021-12-10
CVE-2021-4082 Cross-Site Request Forgery (CSRF) in pimcore/pimcore — pimcore/pimcoreCWE-352 4.3 -2021-12-10
CVE-2021-39189 Observable Response Discrepancy in Lost Password Service — pimcoreCWE-204 5.3 Medium2021-09-15
CVE-2021-39170 Improper Encoding or Escaping of Output in Asset Metadata Component — pimcoreCWE-116 8.0 High2021-09-01
CVE-2021-39166 Improper Neutralization of Text-Values in Object Version Preview — pimcoreCWE-79 8.0 High2021-09-01
CVE-2021-37702 Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore — pimcoreCWE-1236 8.0 High2021-08-18
CVE-2021-31869 Pimcore AdminBundle 'specificID' SQL Injection — Pimcore AdminBundleCWE-89 6.5 Medium2021-08-04
CVE-2021-31867 Pimcore Customer Data Framework 'SegmentAssignmentController.php' Blind SQL Injection — Pimcore Customer Data FrameworkCWE-89 6.5 Medium2021-08-04
CVE-2020-26246 Authorization bypass in Pimcore — pimcoreCWE-285 7.7 High2020-12-03

This page lists every published CVE security advisory associated with pimcore. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.