pimcore/studio-backend-bundle
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pimcore/studio-backend-bundlepage 1 of 1
- CVE-2026-55207HIGHCVSS 8.8EG 8.8✓ Fixed in 2025.4.62026-07-09
vulnerable: v0.10.21 ... v2025.4.5 (16 versions)
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with …
- CVE-2026-55208HIGHCVSS 7.7EG 7.7✓ Fixed in 2025.4.62026-07-09
vulnerable: v0.10.21 ... v2025.4.5 (16 versions)
Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the Date…
- CVE-2026-55212HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.1.62026-07-09
vulnerable: v0.10.21 ... v2026.1.5 (28 versions)
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by the…
Check whether pimcore/studio-backend-bundle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pimcore/studio-backend-bundle CVEs against the assets you own.
Start Free Scan →