Aimeos has 2 CVEs on record. 1 was published in the last 90 days. The median CVSS is 5.6 (medium).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.6
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Products
- Aimeos Laravel ecommerce platform 1
- aimeos/pagible 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2021-47763High· 8.2Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries57CVE-2026-49262Low· 3.0In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding17
Aimeos vulnerabilities
CVEs affecting Aimeos, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-49262Low· 3.0In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) …
▾ Sunlitaimeos · aimeos/pagibleEPSS 0.17%via NVD
CVE-2021-47763High· 8.2PoCAimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries
Aimeos 2021.10 LTS contains a SQL injection vulnerability in the json api 'sort' parameter that allows attackers to inject malicious database queries. Attackers can manipulate the sort parameter to reveal table and column names by sendin…
▾ MidnightAimeos · Aimeos Laravel ecommerce platformEPSS 0.34%via NVD