100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-23495 pimcore/admin-ui-classic-bundle is vulnerable to Improper Access Control in versions 2.0.0-RC1 - 2.2.2 and 0.0.0 - 1.7.15. | 0.0.0 - 1.7.152.0.0-RC1 - 2.2.2 | Medium |
AIKIDO-2025-10427 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. pimcore/admin-ui-classic-bundle is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 2.0.2. | 2.0.0 - 2.0.2 | High |
CVE-2025-30166 pimcore/admin-ui-classic-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.7.6. | 0.0.0 - 1.7.6 | Low |
CVE-2025-24980 pimcore/admin-ui-classic-bundle is vulnerable to Observable Response Discrepancy in versions 0.0.0 - 1.7.4. | 0.0.0 - 1.7.4 | Medium |
CVE-2024-41109 pimcore/admin-ui-classic-bundle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.5.1. | 0.0.0 - 1.5.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.8.4 | — | — |
endroid/qr-code Version ^6.0.1 | — | — |
pimcore/pimcore Version ^12.3 | — | — |
cbschuld/browser.php Version ^1.9.6 | — | — |
phpoffice/phpspreadsheet Version ^2.2 || ^3.3 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant