100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-44741 pimcore/admin-ui-classic-bundle is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.3.5. | 0.0.0 - 2.3.5 | High |
CVE-2026-23495 pimcore/admin-ui-classic-bundle is vulnerable to Improper Access Control in versions 2.0.0-RC1 - 2.2.2 and 0.0.0 - 1.7.15. | 0.0.0 - 1.7.152.0.0-RC1 - 2.2.2 | Medium |
AIKIDO-2025-10427 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. pimcore/admin-ui-classic-bundle is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 2.0.2. | 2.0.0 - 2.0.2 | High |
CVE-2025-30166 pimcore/admin-ui-classic-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.7.6. | 0.0.0 - 1.7.6 | Low |
CVE-2025-24980 pimcore/admin-ui-classic-bundle is vulnerable to Observable Response Discrepancy in versions 0.0.0 - 1.7.4. | 0.0.0 - 1.7.4 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.8.4 | — | — |
endroid/qr-code Version ^6.0.1 | — | — |
pimcore/pimcore Version ^12.3 | — | — |
cbschuld/browser.php Version ^1.9.6 | — | — |
phpoffice/phpspreadsheet Version ^2.2 || ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant