Admin Classic Bundle
Vendor:
First CVE: Jul 11, 2023 · Active for 3 years
14
Total CVEs
More Total CVEs than 91% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Admin Classic Bundle over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2023
3 years ago
Most Recent CVE
Jan 15, 2026
190 days ago
CVE Severity & Scoring
Admin Classic Bundle14 CVEs
57%
29%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (57.1%)
Unknown0 (0.0%)
Required6 (42.9%)
Privileges Required
Low4 (28.6%)
High3 (21.4%)
None7 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24822CRITICAL Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do s | Feb 7, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-23648HIGH Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containin | Jan 24, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-25625CRITICAL Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4 | Feb 19, 2024 | 9.3 | 23 | NO | NO |
CVE-2024-23646HIGH Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch p | Jan 24, 2024 | 8.8 | 22 | NO | NO |
CVE-2023-5844HIGH Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. | Oct 30, 2023 | 7.2 | 22 | NO | NO |
CVE-2023-49075HIGH The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non | Nov 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2024-41109MEDIUM Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pi | Jul 30, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-37280MEDIUM Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this atta | Jul 11, 2023 | 6.1 | 19 | NO | NO |
CVE-2026-23495MEDIUM Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequa | Jan 15, 2026 | 4.3 | 18 | NO | NO |
CVE-2023-46722MEDIUM The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain | Oct 31, 2023 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Admin Classic Bundle
Top CWEs
Versions
No cataloged versions.