pimcore vulnerabilities
CVEs whose affected-version data names the pimcore package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55416High· 8.8Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…
▾ Twilightpimcore · pimcoreEPSS 0.61%via NVD
CVE-2026-55072High· 8.5PoCPimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…
▾ Midnightpimcore · pimcoreEPSS 0.37%via NVD