CoreShop - Pimcore eCommerce
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41249 coreshop/core-shop is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 5.0.0 - 5.0.0. | 5.0.0 - 5.0.0 | High |
AIKIDO-2026-10276 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.0.0 - 4.1.9. | 2.0.0 - 4.1.9 | Low |
CVE-2026-23959 coreshop/core-shop is vulnerable to SQL Injection: Hibernate in versions 0.0.0 - 4.1.9. | 0.0.0 - 4.1.9 | Medium |
CVE-2026-22242 coreshop/core-shop is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 4.1.7. | 0.0.0 - 4.1.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
payum/payum Version 1.7.x-dev | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/form Version ^6.4.14 || ^7.2 | — | — |
symfony/intl Version ^6.4.14 || ^7.2 | — | — |
doctrine/dbal Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant