PKSA-pq1q-v29r-6xp5 Security Advisory
-
[HIGH] Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
PKSA-pq1q-v29r-6xp5 CVE-2026-55208 GHSA-79cw-hfcc-7mw9
Affected package: pimcore/studio-backend-bundle
Affected version: >=2026.1.0,<2026.1.6|<2025.4.6
Reported by:
GitHub