Akeneo develops a product information management platform used to centralize and distribute product data across sales and commerce channels, presenting an application-layer attack surface centered on data handling and integration workflows. The vendor's observed vulnerability signal aligns with web application and scripting contexts, clustering around code injection and OS command injection weaknesses that arise in dynamic content processing and backend command execution. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Akeneo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46157HIGH Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute ar | Dec 9, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-1000009CRITICAL Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution. | Jul 17, 2017 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Akeneo.
Media articles that mention a CVE ID that affects a product developed by Akeneo — matched by CVE ID, not by vendor name.