Vulnerabilities > Pimcore > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-1116 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
network
low complexity
pimcore
5.4
2023-03-01 CVE-2023-1117 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
network
low complexity
pimcore
5.4
2023-02-27 CVE-2023-1067 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.
network
low complexity
pimcore
5.4
2023-02-14 CVE-2023-0827 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17.
network
low complexity
pimcore
5.4
2023-02-03 CVE-2023-23937 Unspecified vulnerability in Pimcore
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (p.e.
network
low complexity
pimcore
5.4
2023-01-16 CVE-2023-0323 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.14.
network
low complexity
pimcore
5.4
2022-09-21 CVE-2022-3255 Cross-site Scripting vulnerability in Pimcore
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user.
network
low complexity
pimcore CWE-79
4.8
2022-09-15 CVE-2022-3211 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6.
network
low complexity
pimcore
5.4
2022-08-23 CVE-2022-2796 Unspecified vulnerability in Pimcore
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4.
network
low complexity
pimcore
4.8
2022-04-14 CVE-2022-1351 Unspecified vulnerability in Pimcore
Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.
network
low complexity
pimcore
5.4