Vulnerabilities (CVE)

Filtered by vendor Pimcore Subscribe
Filtered by product Pimcore
Total 110 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1351 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.
CVE-2022-1339 1 Pimcore 1 Pimcore 2024-11-21 5.0 MEDIUM 7.5 HIGH
SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data
CVE-2022-1219 1 Pimcore 1 Pimcore 2024-11-21 5.0 MEDIUM 7.5 HIGH
SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data
CVE-2022-0911 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0894 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0893 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0832 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-0831 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-0705 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0704 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0665 1 Pimcore 1 Pimcore 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
CVE-2022-0565 1 Pimcore 1 Pimcore 2024-11-21 5.0 MEDIUM 7.6 HIGH
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0510 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0509 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0348 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.
CVE-2022-0285 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.
CVE-2022-0263 1 Pimcore 1 Pimcore 2024-11-21 4.6 MEDIUM 7.8 HIGH
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
CVE-2022-0262 1 Pimcore 1 Pimcore 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.
CVE-2022-0260 1 Pimcore 1 Pimcore 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.
CVE-2022-0258 1 Pimcore 1 Pimcore 2024-11-21 6.5 MEDIUM 8.8 HIGH
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command