Vulnerabilities > Pimcore

DATE CVE VULNERABILITY TITLE RISK
2021-12-21 CVE-2021-4139 Unspecified vulnerability in Pimcore
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
pimcore
critical
9.0
2021-12-10 CVE-2021-4084 Unspecified vulnerability in Pimcore
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
pimcore
6.1
2021-12-10 CVE-2021-4081 Unspecified vulnerability in Pimcore
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
pimcore
6.1
2021-12-10 CVE-2021-4082 Unspecified vulnerability in Pimcore
pimcore is vulnerable to Cross-Site Request Forgery (CSRF)
network
low complexity
pimcore
4.3
2021-09-01 CVE-2021-39166 Unspecified vulnerability in Pimcore
Pimcore is an open source data & experience management platform.
network
low complexity
pimcore
5.4
2021-09-01 CVE-2021-39170 Cross-site Scripting vulnerability in Pimcore
Pimcore is an open source data & experience management platform.
network
low complexity
pimcore CWE-79
5.4
2021-08-18 CVE-2021-37702 Unspecified vulnerability in Pimcore
Pimcore is an open source data & experience management platform.
network
low complexity
pimcore
8.8
2021-08-04 CVE-2021-31867 SQL Injection vulnerability in Pimcore Customer Management Framework
Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application.
network
low complexity
pimcore CWE-89
7.5
2021-08-04 CVE-2021-31869 SQL Injection vulnerability in Pimcore Adminbundle
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application.
network
low complexity
pimcore CWE-89
7.5
2021-07-09 CVE-2021-23405 SQL Injection vulnerability in Pimcore
This affects the package pimcore/pimcore before 10.0.7.
network
low complexity
pimcore CWE-89
8.8