pimcore/admin-ui-classic-bundle
Activity
- Latest release
- 4d ago
- Total releases
- 89
- Cadence
- ~9 days
- Last 12 months
- 19
Reach
- Stars
- 17
Details
- License
- custom
- First release
- Apr 12, 2023
| Version | Released | |
|---|---|---|
v2.3.8
patch
|
v2.3.8
patch
Dependencies (6)
Changelog
Compare changes
|
|
v2.3.7
patch
| ||
v2.3.6
patch
| ||
v2.3.4
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.3.3
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.3.2
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.3.1
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.2.3
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v1.7.16
patch
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.3.0
minor
1 CVE
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev | ||
v2.2.2
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.15
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.2.1
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.14
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.13
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.2.0
minor
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.1.4
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.12
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.1.3
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.1.2
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.10
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.9
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.1.1
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.1.0
minor
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.0.2
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.8
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.7
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.0.1
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.0.0
major
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.0.0-RC3
pre
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v2.0.0-RC1
pre
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.6
patch
2 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev | ||
v1.7.5
patch
3 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev | ||
v1.7.4
patch
3 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev | ||
v1.6.6
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.7.3
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.5
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.4
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.7.2
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.7.1
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.7.0
minor
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.3
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.2
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.1
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.0
minor
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.5.5
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.0-RC2
pre
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.6.0-RC1
pre
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.5.4
patch
4 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev | ||
v1.5.3
patch
5 CVEs
CVE-2026-44741
GHSA-h4ph-crvj-9h92
May 27, 2026
Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
GitHub Security Advisory Draft — GM-369SummarySQL injection in Pimcore's translation grid date filter — the user-supplied SeverityCVSS 3.1: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Component
DescriptionThe translation grid endpoint processes JSON filter parameters. When a filter has
The ImpactAuthenticated user with translations view permission can extract arbitrary database data via UNION-based or error-based SQL injection. Combined with GM-249 (unsafe unserialize), this enables an SQLi → deserialization → RCE chain. Proof of Concept
Suggested FixValidate
References
Suggested FixIn
Proposed Fix
Happy to submit this as a PR against a private fork if that is the preferred workflow. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 76 more Show less
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.16
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.18
2.3.6
References
Updated Jul 10, 2026 · Source: OSV.dev
CVE-2026-23495
GHSA-hqrp-m84v-2m2f
Jan 15, 2026
Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryThe API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment. DetailsThe backend user without permission was still able to list "Predefined Properties" item Step to Reproduce the issuelogin as Admin (full permission) and clicked "Predefined Properties" Then, captured and saved the request:
Next, login a backend user with no permission The copy the "Cookie" and "X-Pimcore-Csrf-Token" After that, pasted the copied "Cookie" and "X-Pimcore-Csrf-Token" to captured request -List API
ImpactExploitation allows low-privileged users to enumerate all Predefined Properties, exposing internal metadata schemas, default values, and configuration details that may reveal business logic, data classification strategies, or sensitive defaults (e.g., proprietary keys or select options). In a PIM system like Pimcore, this could facilitate reconnaissance for further attacks, such as targeted data manipulation or privilege escalation, leading to unauthorized alterations of asset/object properties. For organizations handling regulated content (e.g., e-commerce catalogs under GDPR or PCI DSS), such exposure risks compliance breaches, intellectual property leakage, and operational inconsistencies from unintended property overrides. Affected versions
2.0.0-RC2
v2.0.0
v2.0.0-RC1
v2.0.0-RC3
v2.0.0-RC4
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
+ 69 more Show less
v2.2.0
v2.2.1
v2.2.2
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.10
v1.7.12
v1.7.13
v1.7.14
v1.7.15
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
Fixed in
1.7.16
2.2.3
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-30166
GHSA-x82r-6j37-vrgg
Apr 08, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
Network
High
High
SummaryAn HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. DetailsThe vulnerability was discovered in the PoCTo reproduce the vulnerability, a user must fill out the email's content form with the desired HTML payload.
ImpactThis HTML injection vulnerability can potentially enable phishing attacks by allowing the insertion of any html like fake login forms, etc.
All functionalities that process user input should be carefully reviewed to ensure that data is appropriately encoded as HTML entities in server responses. For instance, a reflected input paramete like Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 45 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
Fixed in
1.7.6
References Updated Apr 08, 2025 · Source: OSV.dev
CVE-2025-24980
GHSA-vr5f-php7-rg24
Feb 07, 2025
Pimcore Admin Classic Bundle allows user enumeration
Medium
Network
Low
None
None
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability. Affected versions
1.4.0
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
+ 43 more Show less
v1.1.0-RC1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
Fixed in
1.7.4
References
Updated Feb 11, 2025 · Source: OSV.dev
GHSA-hq76-662x-7mw4
Sep 03, 2024
Pimcore includes vulnerable PHPOffice/PhpSpreadsheet
High
Network
Low
None
SummaryPimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: GHSA-ghg6-32f9-2jp7. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.0-RC1
+ 26 more Show less
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.0-RC1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0
v1.5.1
v1.5.2
v1.5.3
Fixed in
1.3.11
1.4.7
1.5.4
References Updated Dec 05, 2024 · Source: OSV.dev |