pimcore/pimcore vulnerabilities
CVEs whose affected-version data names the pimcore/pimcore package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…
CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…
CVE-2026-11407High· 7.2Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed