Pimcore
142 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Pimcore, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Pimcore CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 5 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 8 |
| 2026-08 | 3 |
| 2026-09 | 2 |
Severity
How the 142 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High46
- Medium87
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Pimcore.
- CVE-2026-55416Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fields Without Parameterization8.8
- CVE-2026-55072Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name8.5
- CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Name9.9
- CVE-2026-55220Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column—
- CVE-2026-44741Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter8.8
- CVE-2026-45704Pimcore: CustomReports Share Bypass—
- CVE-2026-44739Pimcore: SQL Injection in Custom Reports Column Configuration8.7
- CVE-2026-45260Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling8.1
- CVE-2026-45703Pimcore: WordExport Authorization Bypass for Unauthorized Document Export6.4
- CVE-2026-45162Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction8.0
- CVE-2026-55207Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass8.8
- CVE-2026-55208Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes7.7
- CVE-2026-55212Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation7.1
- CVE-2026-5362Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering5.4
- CVE-2026-5394Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling—
Product grouping is registry-driven, with AI assist and human review. How it works