pimcore/pimcore is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
The Video document editable uses the YouTube and Dailymotion video id in the src of the generated <iframe> without HTML escaping. A backend user who sets a crafted video id can break out of the attribute and inject markup that runs as script in editmode and on the frontend, leading to stored cross-site scripting against editors and site visitors. The fix passes the YouTube and Dailymotion ids through htmlspecialchars before building the iframe src.
You are affected if you are using a version that falls within the vulnerable range and your site uses Video document editables whose YouTube or Dailymotion id can be set by an untrusted backend user.
pimcore/pimcore is vulnerable to Cross-Site Scripting (XSS) in versions 2.2.0 - 2026.2.11.
Upgrade the pimcore/pimcore library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.