Pimcore
Pimcore Admin Classic Bundle: vulnerabilities and CVEs
Pimcore Admin Classic Bundle has 15 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months2
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44741 | High (8.8) | 0.50% | — | Aug 12, 2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from… |
| CVE-2026-23495 | Medium (4.3) | 0.36% | — | Jan 15, 2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks.… |
| CVE-2025-30166 | Low (1.8) | 0.25% | — | Apr 8, 2025 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin… |
| CVE-2025-24980 | Medium (6.9) | 0.52% | — | Feb 7, 2025 | pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic… |
| CVE-2024-41109 | Medium (6.5) | 0.48% | — | Jul 30, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL… |
| CVE-2024-25625 | Critical (9.3) | 0.68% | — | Feb 19, 2024 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host… |
| CVE-2024-24822 | Critical (9.1) | 0.54% | — | Feb 7, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3.… |
| CVE-2024-23646 | High (8.8) | 1.00% | — | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter… |
| CVE-2024-23648 | High (8.8) | 0.83% | — | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL… |
| CVE-2023-49075 | High (7.2) | 1.4% | — | Nov 28, 2023 | The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An… |
| CVE-2023-47636 | Medium (5.3) | 0.65% | — | Nov 15, 2023 | The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. Certain… |
| CVE-2023-46722 | Medium (6.1) | 0.50% | — | Oct 31, 2023 | The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's… |
| CVE-2023-5844 | High (7.2) | 0.55% | — | Oct 30, 2023 | Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. |
| CVE-2023-42817 | Medium (5.4) | 0.38% | — | Sep 25, 2023 | Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user.… |
| CVE-2023-37280 | Medium (6.1) | 0.58% | — | Jul 11, 2023 | Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.