pimcore/pimcore Security Advisories for v11.0.0-RC2 (20)
-
[HIGH] Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
PKSA-pmf2-z78s-582m CVE-2026-55416 GHSA-23rh-xw42-fq82
Affected version: <11.5.18|>=12.0.0-RC1,<=12.3.9|>=2026.1.0,<=2026.1.5
Reported by:
GitHub -
[CRITICAL] Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
PKSA-vgg9-cbdg-s4xt CVE-2026-55634 GHSA-9x44-4gxf-8c25
Affected version: >=2026.1.0,<=2026.1.5|<=12.3.9
Reported by:
GitHub -
[CRITICAL] Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
PKSA-kkjc-bw16-f3kq CVE-2026-55220 GHSA-w23p-wrp7-ch38
Affected version: <=12.3.9|>=2026.1.0,<=2026.1.5
Reported by:
GitHub -
[HIGH] Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
PKSA-fpxc-s2d8-24zv CVE-2026-55072 GHSA-2mhj-fhvg-v428
Affected version: <12.3.9|>=2026.1.0,<=2026.1.4
Reported by:
GitHub -
[HIGH] Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
PKSA-6dhb-gq75-qpgr CVE-2026-11407 GHSA-7p36-fq2r-4h7r
Affected version: <=11.5.14.1|>=12.0.0-RC1,<=12.3.8
Reported by:
GitHub -
[HIGH] Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import/save
PKSA-vp19-ydt7-tws9 CVE-2026-5394 GHSA-r2f4-ff2p-xc64
Affected version: >=2026.1.0,<2026.1.3|<=11.5.16|>=12.0.0-RC1,<=12.3.6
Reported by:
GitHub -
[HIGH] Pimcore has a CustomReports Share Bypass
PKSA-vd5r-2gyh-m6cc CVE-2026-45704 GHSA-jwcc-gv4m-93x6
Affected version: >=2026.1.0,<2026.1.2|<=11.5.16|>=12.0.0-RC1,<=12.3.5
Reported by:
GitHub -
[MEDIUM] Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export
PKSA-v5bg-33q7-q8zj CVE-2026-45703 GHSA-332x-r494-54fq
Affected version: >=2026.1.0,<2026.1.3|<=11.5.16|>=12.0.0-RC1,<=12.3.6
Reported by:
GitHub -
[HIGH] Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
PKSA-y4yc-6g1b-qfqz CVE-2026-45260 GHSA-wc7j-g8wx-m2qx
Affected version: <=11.5.16|>=2026.1.0,<2026.1.3|>=12.0.0-RC1,<=12.3.6
Reported by:
GitHub -
[HIGH] Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
PKSA-882j-k212-wjbf CVE-2026-45162 GHSA-36fc-7wjg-mfvj
Affected version: >=2026.1.0,<2026.1.3|<=11.5.16|>=12.0.0-RC1,<=12.3.6
Reported by:
GitHub -
[HIGH] Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration
PKSA-kp19-xmdp-rvyj CVE-2026-44739 GHSA-3234-gxc3-pq6f
Affected version: >=12.0.0-RC1,<=12.3.5|<=11.5.16|>=2026.1.0,<2026.1.2
Reported by:
GitHub -
[MEDIUM] Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause
PKSA-8x4n-f9v2-4s1d CVE-2026-27461 GHSA-vxg3-v4p6-f3fp
Affected version: >=12.0.0,<12.3.3|<=11.5.14.1
Reported by:
GitHub -
[MEDIUM] Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on "Static Routes" Listing
PKSA-88th-p7sv-k9g4 CVE-2026-23494 GHSA-m3r2-724c-pwgf
Affected version: <=11.5.13|>=12.0.0-RC1,<=12.3
Reported by:
GitHub -
[HIGH] Pimcore ENV Variables and Cookie Informations are exposed in http_error_log
PKSA-9ss4-dj21-s7vh CVE-2026-23493 GHSA-q433-j342-rp9h
Affected version: <=11.5.13|>=12.0.0-RC1,<=12.3
Reported by:
GitHub -
[HIGH] Pimcore Has an Incomplete Patch for CVE-2023-30848
PKSA-hpvp-zv9c-rrr4 CVE-2026-23492 GHSA-qvr7-7g55-69xj
Affected version: <=11.5.13|>=12.0.0-RC1,<12.3.1
Reported by:
GitHub -
[MEDIUM] Pimcore Vulnerable to SQL Injection in getRelationFilterCondition
PKSA-2dyk-44y3-3rzz CVE-2025-27617 GHSA-qjpx-5m2p-5pgh
Affected version: <11.5.4
Reported by:
GitHub -
[HIGH] Flooding Server with Thumbnail files
PKSA-2ws5-72xf-nzn8 CVE-2024-32871 GHSA-277c-5vvj-9pwx
Affected version: >=11.0.0,<11.2.4
Reported by:
GitHub -
[MEDIUM] Pimcore TinyMCE Bundle - tinymce CVE-2024-29203, CVE-2024-29881
PKSA-8cp9-pysj-5xkk GHSA-vjwg-28gv-pm8h
Affected version: >=11.0.0-ALPHA1,<11.1.6.5|>=11.2.0,<11.2.3
Reported by:
GitHub -
[HIGH] Pimcore SQL Injection in Admin Grid Filter API through Multiselect::getFilterConditionExt()
PKSA-d1ts-d4yt-xjz4 CVE-2023-47637 GHSA-72hh-xf79-429p
Affected version: <11.1.1
Reported by:
GitHub -
[MEDIUM] Pimcore Cross-site Scripting vulnerability
PKSA-17vx-xhyz-z3x1 CVE-2023-5873 GHSA-j59v-hh4p-q92m
Affected version: <11.1.0
Reported by:
GitHub