CoreShop - Pimcore eCommerce
98%
Total Score
95
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10276 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.0.0 - 4.1.9. | 2.0.0 - 4.1.9 | Low |
CVE-2026-23959 coreshop/core-shop is vulnerable to SQL Injection: Hibernate in versions 0.0.0 - 4.1.9. | 0.0.0 - 4.1.9 | Medium |
CVE-2026-22242 coreshop/core-shop is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 4.1.7. | 0.0.0 - 4.1.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
payum/payum Version 1.7.x-dev | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^6.3 || ^7.0 | — | — |
symfony/intl Version ^6.3 || ^7.0 | — | — |
doctrine/dbal Version ^4.2 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant