coreshop/core-shop
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting coreshop/core-shoppage 1 of 1
- CVE-2026-22242MEDIUMCVSS 4.9EG 4.9✓ Fixed in 4.1.82026-01-08
vulnerable: 1.0.0 ... v0.2 (145 versions)
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based…
- CVE-2026-23959MEDIUMCVSS 4.9EG 4.9✓ Fixed in 4.1.92026-01-22
vulnerable: 1.0.0 ... v0.2 (146 versions)
CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` within the CoreShop admin panel. The affected endpoint improperl…
Check whether coreshop/core-shop is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for coreshop/core-shop CVEs against the assets you own.
Start Free Scan →