Known vulnerabilities in Pimcore Studio Backend bundle
Vendor:
Pimcore
Software:
Pimcore Studio Backend bundle
Software CPE:
cpe:2.3:a:pimcore:studio-backend-bundle:*:*:*:*:*:pimcore:*:*
Website:
https://pimcore.com/en
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
2026.2.6
2025.4.11
2026.2.5
2025.4.10
2026.2.4
2026.2.3
2026.2.2
2025.4.9
2025.4.8
2026.2.1
2026.2.0
2025.4.7
2026.1.6
2026.1.5
2026.1.4
2026.1.3
2026.1.2
2026.1.1
2026.1.0
2025.4.6
2025.4.5
2025.4.4
2025.4.3
2025.4.2
2025.4.1
2025.4.0
0.15.17
0.14.19
0.13.20
0.12.18
0.12.9
0.10.21
0.9.30
0.6.30
0.5.20
0.4.30
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135786 - Weak password recovery mechanism CVE-2026-55207 |
CWE-640 | High | 2025.4.6, 2026.1.6 | 29.06.2026 |
SB2026062994 |
||
| #VU135785 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-55208 |
CWE-89 | Low | 2025.4.6, 2026.1.6 | 29.06.2026 |
SB2026062994 |
||
| #VU135784 - Improper Authorization CVE-2026-55212 |
CWE-285 | Low | 2025.4.6, 2026.1.6 | 29.06.2026 |
SB2026062994 |