pimcore has 7 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 8.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-89 (4). Most affected products: pimcore/pimcore (3), pimcore (2), pimcore/studio-backend-bundle (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 6 prev 1
Weakness classes
Products
- pimcore/pimcore 3
- pimcore 2
- pimcore/studio-backend-bundle 2
Worst active — by depth score
CVE-2026-55072High· 8.5Pimcore is an Open Source Data & Experience Management Platform59CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform55CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform52CVE-2026-55416High· 8.8Pimcore is an Open Source Data & Experience Management Platform49CVE-2026-55207High· 8.8Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass49
pimcore vulnerabilities
CVEs affecting pimcore, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-55416High· 8.8Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…
CVE-2026-55072High· 8.5PoCPimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…
CVE-2026-55207High· 8.8Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…
CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…
CVE-2026-11407High· 7.2Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed