CVE-2026-55416High· 8.8▾ TwilightPimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these values into a database query, while a blacklist omits dangerous constructs such as additional data-manipulation statements, comments, subqueries, and multiple statements. The getData() method also previously interpolated offset and limit values into a LIMIT clause without integer casting. Executing the configured report reaches fetchAllAssociative() with the constructed query and can disclose, modify, or delete arbitrary database data. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
pimcore/pimcore >= 2026.1.0, <= 2026.1.5pimcore/pimcore >= 12.0.0-RC1, <= 12.3.9pimcore/pimcore < 11.5.18Patched in:
pimcore/pimcore 2026.1.6pimcore/pimcore 12.3.10pimcore/pimcore 11.5.19Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55072High· 8.5Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
CVE-2025-15392Medium· 6.3A weakness has been identified in Kohana KodiCMS up to 13.82.135
CVE-2025-13811Medium· 6.3A vulnerability was determined in jsnjfz WebStack-Guns 1.0