VendorsPimcorecustomer_management_frameworkall versions
Vulnerabilities

Pimcore Customer Management Framework

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-2629
Improper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-framework
Published 2023-05-10 · Modified
7.8EPSS 0.004
CVE-2021-31867
Pimcore Customer Data Framework 'SegmentAssignmentController.php' Blind SQL Injection
Published 2021-08-04 · Modified
7.5EPSS 0.012
CVE-2023-2756
SQL Injection in pimcore/customer-data-framework
Published 2023-05-17 · Modified
7.2EPSS 0.009
CVE-2023-2881
Storing Passwords in a Recoverable Format in pimcore/customer-data-framework
Published 2023-05-25 · Analyzed
6.7EPSS 0.005
CVE-2023-4145
Cross-site Scripting (XSS) - Stored in pimcore/customer-data-framework
Published 2023-08-03 · Analyzed
6.5EPSS 0.006
CVE-2024-21667
Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access GDPR extracts
Published 2024-01-11 · Modified
6.5EPSS 0.006
CVE-2024-21666
Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates list
Published 2024-01-11 · Modified
6.5EPSS 0.006
CVE-2023-3574
Improper Authorization in pimcore/customer-data-framework
Published 2023-07-10 · Modified
6.5EPSS 0.005
CVE-2023-32075
Pimcore vulnerable to Business Logic Errors in Customer automation rules
Published 2023-05-11 · Modified
4.3EPSS 0.008