Pimcore is a content management and digital experience platform that, despite a narrow product portfolio, occupies a prominent position in enterprise content and product-information management. Its vulnerabilities concentrate in the core Pimcore platform and related administrative and customer-data bundles, and center on web application input-handling and access-control weaknesses including cross-site scripting, SQL injection, path traversal, and improper access control—a characteristic pattern for server-side content platforms handling user-supplied data and role-based administration. A moderate tendency toward public exploit availability reflects the vendor's exposure as an enterprise-facing application; defenders should prioritize regular patching of exposed instances and restrict administrative access. Remediation often requires coordinated updates across Pimcore's bundle ecosystem, since the platform's integration depth means a flaw in administrative or data-layer components can propagate across dependent features. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pimcore over time
Signals from CVEs in this vendor scope (155 CVEs).
155 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10867HIGH An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the | Apr 4, 2019 | 8.8 | 82 | NO | YES |
CVE-2023-1578HIGH SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. | Mar 22, 2023 | 8.8 | 64 | NO | NO |
CVE-2022-1429HIGH SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data | Apr 22, 2022 | 7.5 | 60 | NO | NO |
CVE-2018-14058MEDIUM Pimcore before 5.3.0 allows SQL Injection via the REST web service API. | Aug 17, 2018 | 6.5 | 56 | NO | YES |
CVE-2022-0832MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. | Mar 4, 2022 | 5.4 | 47 | NO | NO |
CVE-2018-14057HIGH Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the " | Aug 17, 2018 | 8.8 | 39 | NO | YES |
CVE-2022-39365CRITICAL Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout | Oct 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2014-2921HIGH The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lu | Apr 21, 2014 | 7.5 | 31 | NO | YES |
CVE-2024-11956HIGH A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file / | Jan 28, 2025 | 7.2 | 30 | NO | YES |
CVE-2019-18981CRITICAL Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification. | Nov 15, 2019 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (155 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pimcore.
Media articles that mention a CVE ID that affects a product developed by Pimcore — matched by CVE ID, not by vendor name.