Coreshop is an e-commerce platform with a focused product footprint, and its observed vulnerabilities center on database-layer input handling through SQL injection weaknesses, including both Hibernate-specific and general SQL command injection vectors. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coreshop over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23959MEDIUM CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` withi | Jan 22, 2026 | 4.9 | 22 | NO | NO |
CVE-2026-22242MEDIUM CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator- | Jan 8, 2026 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coreshop.
Media articles that mention a CVE ID that affects a product developed by Coreshop — matched by CVE ID, not by vendor name.