Loading HuntDB...

Vulnerabilities

CVE-2022-0510

MEDIUM

Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.

Published Feb 08, 2022

CVE-2022-0509

MEDIUM

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

Published Feb 08, 2022

CVE-2022-0348

MEDIUM

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

Published Jan 27, 2022

CVE-2022-0251

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.

Published Jan 26, 2022

CVE-2022-0285

MEDIUM

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

Published Jan 20, 2022

CVE-2022-0263

MEDIUM

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

Published Jan 18, 2022

CVE-2022-0262

MEDIUM

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

Published Jan 18, 2022

CVE-2021-4146

MEDIUM

Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.

Published Jan 18, 2022

CVE-2022-0260

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.

Published Jan 18, 2022

CVE-2022-0257

MEDIUM

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Jan 17, 2022

CVE-2022-0258

HIGH

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

Published Jan 17, 2022

CVE-2022-0256

MEDIUM

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Jan 17, 2022

CVE-2021-4139

MEDIUM

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 21, 2021

CVE-2021-4084

HIGH

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 10, 2021

CVE-2021-4081

MEDIUM

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 10, 2021

CVE-2021-4082

MEDIUM

pimcore is vulnerable to Cross-Site Request Forgery (CSRF)

Published Dec 10, 2021

CVE-2021-39189

MEDIUM

Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

Published Sep 15, 2021

CVE-2021-39170

HIGH

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

Published Sep 01, 2021

CVE-2021-39166

HIGH

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly escaped before printed in the version preview. This allowed XSS by authenticated users with access to the resources. This issue is patched in Pimcore version 10.1.2.

Published Sep 01, 2021

CVE-2021-37702

HIGH

Pimcore is an open source data & experience management platform. Prior to version 10.1.1, Data Object CSV import allows formular injection. The problem is patched in 10.1.1. Aside from upgrading, one may apply the patch manually as a workaround.

Published Aug 18, 2021

CVE-2021-31869

MEDIUM

Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.

Published Aug 04, 2021

CVE-2021-31867

MEDIUM

Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.

Published Aug 04, 2021

CVE-2020-26246

HIGH

Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

Published Dec 03, 2020