Vulnerabilities > Pimcore > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-22 CVE-2022-1429 SQL Injection vulnerability in Pimcore
SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6.
network
low complexity
pimcore CWE-89
5.0
2022-04-13 CVE-2022-1339 SQL Injection vulnerability in Pimcore
SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5.
network
low complexity
pimcore CWE-89
5.0
2022-04-08 CVE-2022-1219 SQL Injection vulnerability in Pimcore
SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5.
network
low complexity
pimcore CWE-89
5.0
2022-02-22 CVE-2022-0665 Path Traversal vulnerability in Pimcore
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
network
low complexity
pimcore CWE-22
5.5
2022-02-14 CVE-2022-0565 Cross-site Scripting vulnerability in Pimcore
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
network
low complexity
pimcore CWE-79
6.4
2022-01-18 CVE-2021-4146 Unspecified vulnerability in Pimcore
Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.
network
low complexity
pimcore
4.0
2022-01-18 CVE-2022-0262 Cross-site Scripting vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.
network
pimcore CWE-79
4.3
2022-01-18 CVE-2022-0263 Unrestricted Upload of File with Dangerous Type vulnerability in Pimcore
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
local
low complexity
pimcore CWE-434
4.6
2022-01-17 CVE-2022-0258 SQL Injection vulnerability in Pimcore
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
network
low complexity
pimcore CWE-89
6.5
2021-12-21 CVE-2021-4139 Cross-site Scripting vulnerability in Pimcore
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
pimcore CWE-79
6.0