Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pimcore — Vulnerabilities & Security Advisories 145

Browse all 145 CVE security advisories affecting pimcore. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pimcore is an open-source digital experience platform primarily used for product information management and digital asset management. Its architecture, built on Symfony, exposes it to typical web application vulnerabilities. Historical Common Vulnerabilities and Exposures records indicate a prevalence of remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from insufficient input validation and improper access controls within its content management modules. While no single catastrophic breach has defined its public history, the high volume of disclosed CVEs suggests persistent challenges in securing its complex feature set. Security assessments frequently highlight risks related to outdated dependencies and configuration errors. Organizations deploying this platform must prioritize rigorous patch management and continuous vulnerability scanning to mitigate the inherent risks associated with its extensive functionality and frequent updates.

Found 1 results / 145Clear Filters
HighCVE-2026-447412026-08-13
SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter · Advisory · pimcore/pimcore · GitHub
Unknown2026-08-13
[Security]: Update unserialize to use allowed_classes option in Dashboard by kingjia90 · Pull Request #1111 · pimcore/ad
HighCVE-2024-457042026-07-18
CustomReports Share Bypass · Advisory · pimcore/pimcore · GitHub
HighGHSA-jwcc-gv4m-93x62026-07-18
[Security] Enhance Custom Report controller actions by kingjia90 · Pull Request #19099 · pimcore/pimcore · GitHub
Unknown2026-07-18
[Security] Enhance Custom Report controller actions (#19099) · pimcore/pimcore@1893ff1 · GitHub
High2026-07-18
[Security]Enhance Authorization in WebDAV MOVE via unchecked asset move handling by kingjia90 · Pull Request #19120 · pi
High2026-07-18
[Security]Enhance Authorization in WebDAV MOVE via unchecked asset mo… · pimcore/pimcore@9d7c77f · GitHub
HighCVE-2025-62802026-07-18
Missing Authorization in WebDAV MOVE via unchecked asset move handling · Advisory · pimcore/pimcore · GitHub
HighCVE-2024-477392026-07-18
SQL Injection in Custom Reports Column Configuration · Advisory · pimcore/pimcore · GitHub
Unknown2026-07-18
[Security]: Enhance SQL security in Custom Report (#19098) · pimcore/pimcore@3fd7733 · GitHub
MediumCVE-2024-457032026-07-18
WordExport Authorization Bypass for Unauthorized Document Export · Advisory · pimcore/pimcore · GitHub
High2026-07-18
[Security]: Harden unserializer and refine allowed classes (#19119) · pimcore/pimcore@4788bf3 · GitHub
HighCVE-2026-451822026-07-18
Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction · Advisory · pimcore/pimcore · GitH
High2026-07-10
Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation · Advisory · pimcore/pim
Unknown2026-07-10
[Bug] [User Permissions] Update access control for class definition r… · pimcore/studio-backend-bundle@d1a4788 · GitHub
HighCVE-2026-52582026-07-10
# SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including adm
High2026-07-10
add improvements for listing filters (#1883) · pimcore/studio-backend-bundle@f532428 · GitHub
High2026-07-10
add URL validation for reset password link (#1882) · pimcore/studio-backend-bundle@ea9d329 · GitHub
High2026-07-10
Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA b
High2026-06-18
Fix: add method and property check to twig SecurityPolicy by robertSt7 · Pull Request #19193 · pimcore/pimcore · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with pimcore. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.