pimcore/studio-backend-bundle vulnerabilities
CVEs whose affected-version data names the pimcore/studio-backend-bundle package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55207High· 8.8Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.67%via GHSA
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.41%via GHSA