VulnSea

pimcore has 7 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 8.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-89 (4). Most affected products: pimcore/pimcore (3), pimcore (2), pimcore/studio-backend-bundle (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.7
Publish → KEV
Last 90 days
6 prev 1

Products

  • pimcore/pimcore 3
  • pimcore 2
  • pimcore/studio-backend-bundle 2
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

pimcore vulnerabilities

CVEs affecting pimcore, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-55416High· 8.8
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…

Twilightpimcore · pimcoreEPSS 0.61%via NVD
CVE-2026-55072High· 8.5PoC
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

Midnightpimcore · pimcoreEPSS 0.37%via NVD
CVE-2026-55207High· 8.8
3w ago

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.67%via GHSA
CVE-2026-55208High· 7.7
3w ago

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.41%via GHSA
CVE-2026-55220Critical
3w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspot…

Midnightpimcore · pimcore/pimcoreEPSS 0.50%via NVD
CVE-2026-55634Critical· 9.9
3w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

Midnightpimcore · pimcore/pimcoreEPSS 0.45%via NVD
CVE-2026-11407High· 7.2
3mo ago

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Twilightpimcore · pimcore/pimcoreEPSS 0.62%via GHSA
pimcore vulnerabilities (CVEs) · VulnSea