CVE-2026-55634Critical· 9.9▾ MidnightPimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and by models/DataObject/ClassDefinition/Helper/Dao.php into ALTER TABLE identifiers. An authenticated user with the objects permission can inject PHP syntax into the generated DataObject class, causing attacker-controlled code in generated var/classes/DataObject/.php files to run when an object of that class is instantiated, and can also inject SQL identifier content into schema-changing statements. The central models/DataObject/ClassDefinition/Data.php::setName() validation did not reject semicolons, braces, backticks, spaces, or other non-identifier characters. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
pimcore/pimcore <= 12.3.9pimcore/pimcore >= 2026.1.0, <= 2026.1.5Patched in:
pimcore/pimcore 12.3.10pimcore/pimcore 2026.1.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55416High· 8.8Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
CVE-2026-55072High· 8.5Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-11407High· 7.2Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVE-2025-13811Medium· 6.3A vulnerability was determined in jsnjfz WebStack-Guns 1.0