These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-45704 is a high-severity vulnerability in Pimcore's CustomReports feature, allowing low-privileged backend users with reports permission to access unshared reports, potentially exposing sensitive data such as report names, grouping information, display and icon metadata, data source configurations, column configurations, and sharing settings. This issue is fixed in versions 11.5.17 (LTS) and 12.3 [truncated]
CVE-2026-45260 is a high-severity vulnerability in Pimcore's WebDAV asset endpoint. Prior to versions 11.5.17 (LTS) and 12.3.7, the endpoint exposes a MOVE operation without an authentication plugin, allowing unauthorized asset deletion, moves, or overwrites. This could lead to data loss or corruption. The issue is fixed in versions 11.5.17 (LTS) and 12.3.7. Users of Pimcore, especially those using WebDAV [truncated]
CVE-2026-45703 is a security vulnerability in Pimcore's WordExport export flow. Prior to versions 11.5.17 (LTS) and 12.3.7, a low-privileged backend user could export document content they were not allowed to view due to insufficient permission checks. This vulnerability has a CVSS score of 6.4 and is classified as MEDIUM severity. The vulnerability is caused by the WordExport export flow not properly enf [truncated]
CVE-2026-45162 is a remote code execution vulnerability in Pimcore, an Open Source Data & Experience Management Platform. The vulnerability exists due to multiple locations in Pimcore calling PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction. This allows an attacker to inject malicious objects and execute remote code if they can control the seri [truncated]
The Pimcore Studio API class definition creation endpoint has a permission issue. Prior to versions 2025.4.6 and 2026.1.6, the endpoint is guarded by object permission instead of class permission. This allows a standard editor-level user to create class definitions without admin privileges, potentially leading to unauthorized database table and PHP class file creation. The vulnerability exists due to inco [truncated]
CVE-2026-55207 is a high-severity vulnerability in Pimcore, an Open Source Data & Experience Management Platform. An unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link t [truncated]
A stored cross-site scripting (XSS) vulnerability in Pimcore v12.3.3 allows authenticated attackers with document editing permissions to inject malicious HTML/JavaScript through the Document embed editable feature. The payload executes when published pages are rendered, potentially compromising session tokens or performing actions on behalf of victims. The CVSS 4.0 score of 4.8 (Medium) reflects network a [truncated]