« Back to list

Pimcore

Pimcore Admin Classic Bundle: vulnerabilities and CVEs

Pimcore Admin Classic Bundle has 15 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs15
Last 12 months2
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-44741High (8.8)0.50%—Aug 12, 2026
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from…
CVE-2026-23495Medium (4.3)0.36%—Jan 15, 2026
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks.…
CVE-2025-30166Low (1.8)0.25%—Apr 8, 2025
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin…
CVE-2025-24980Medium (6.9)0.52%—Feb 7, 2025
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic…
CVE-2024-41109Medium (6.5)0.48%—Jul 30, 2024
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL…
CVE-2024-25625Critical (9.3)0.68%—Feb 19, 2024
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host…
CVE-2024-24822Critical (9.1)0.54%—Feb 7, 2024
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3.…
CVE-2024-23646High (8.8)1.00%—Jan 24, 2024
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter…
CVE-2024-23648High (8.8)0.83%—Jan 24, 2024
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL…
CVE-2023-49075High (7.2)1.4%—Nov 28, 2023
The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An…
CVE-2023-47636Medium (5.3)0.65%—Nov 15, 2023
The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain…
CVE-2023-46722Medium (6.1)0.50%—Oct 31, 2023
The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's…
CVE-2023-5844High (7.2)0.55%—Oct 30, 2023
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
CVE-2023-42817Medium (5.4)0.38%—Sep 25, 2023
Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user.…
CVE-2023-37280Medium (6.1)0.58%—Jul 11, 2023
Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Pimcore