Customer Management Framework
Vendor:
First CVE: Aug 4, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Customer Management Framework over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 4, 2021
4 years ago
Most Recent CVE
Jan 11, 2024
924 days ago
CVE Severity & Scoring
Customer Management Framework9 CVEs
67%
33%
All CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low4 (44.4%)
High2 (22.2%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2629HIGH Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. | May 10, 2023 | 7.8 | 25 | NO | NO |
CVE-2021-31867HIGH Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php compone | Aug 4, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-2756HIGH SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | May 17, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-3574MEDIUM Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | Jul 10, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-21667MEDIUM pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data | Jan 11, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-21666MEDIUM The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and un | Jan 11, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-2881MEDIUM Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | May 25, 2023 | 4.9 | 18 | NO | NO |
CVE-2023-32075MEDIUM The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, busin | May 11, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-4145MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2. | Aug 3, 2023 | 5.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Customer Management Framework
Top CWEs
Versions
No cataloged versions.