GHSA-qxcw-rf4v-hp26
GitHub Security Advisory
Pimcore vulnerable to Cross Site Scripting in image/video thumbnail config
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
An attacker can use XSS to send a malicious script to any user through Image/Video thumbnail config
### Patches
Update to version 10.5.18 or apply this patch manually https://github.com/pimcore/pimcore/pull/14472.patch
### Workarounds
Apply https://github.com/pimcore/pimcore/pull/14472.patch manually.
### References
https://huntr.dev/bounties/e8c0044d-a31b-4347-b2d5-59fbf492da39/
Affected Packages
Packagist
pimcore/pimcore
Affected versions:
0
(fixed in 10.5.18)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.