← Vulnerability feed

Vulnerability record · CVE-2022-0832 · published 4 March 2022

CVE-2022-0832: Pimcore stored XSS before 10.3.3

Pimcore · Pimcore

Pimcore versions prior to 10.3.3 contain a stored cross-site scripting flaw (CWE-79) in the GitHub repository pimcore/pimcore. Injected script content persists and executes in the browsers of users who view the affected page, so it matters for any deployment where untrusted content reaches stored fields. The record gives no further detail on the specific vulnerable component or input.

5.4 CVSS 3.1 Medium EPSS 67% · top 0.7% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS rates it medium (5.4) and it requires privileges plus user interaction, but the very high EPSS percentile and public exploit reference raise the practical urgency.

What it is

Pimcore versions prior to 10.3.3 contain a stored cross-site scripting flaw (CWE-79) in the GitHub repository pimcore/pimcore. Injected script content persists and executes in the browsers of users who view the affected page, so it matters for any deployment where untrusted content reaches stored fields. The record gives no further detail on the specific vulnerable component or input.

Impact

An attacker can run script in the context of a victim's session, enabling session or data theft and actions performed as the victim. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network (AV:N) with low attack complexity, but it requires low privileges (PR:L) and user interaction (UI:R) for the victim to trigger the stored payload. No authentication bypass is implied; the attacker needs an account able to store the malicious content.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6662 (99.25th percentile), indicating elevated predicted exploitation activity. The references include an Exploit-tagged huntr bounty and a patch commit, so public proof-of-concept detail likely exists.

What to do

  • Upgrade Pimcore to 10.3.3 or later, applying the referenced patch commit.
  • Restrict accounts that can create or edit stored content to trusted users and review existing roles.
  • Apply output encoding and input sanitization for stored fields, and enforce a Content Security Policy to limit script execution.
  • Review stored content for injected script payloads and remove any found.

Detection

  • Search application and web logs for requests containing script tags or event-handler attributes in stored fields.
  • Monitor for anomalous script execution or unexpected outbound requests from authenticated Pimcore sessions.
  • Audit stored content records for HTML/JavaScript payloads introduced around suspicious edit times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0832 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-39365Pimcore code injection vulnerabilityPimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/…EPSS 1.8%9.8CVE-2019-18981Pimcore vulnerabilityPimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.EPSS 1.4%9.8CVE-2019-18985Pimcore improper restriction of authentication attempts vulnerabilityPimcore before 6.2.2 lacks brute force protection for the 2FA token.EPSS 1.4%9.0CVE-2021-4139Pimcore cross-site scripting vulnerabilitypimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.88%8.8CVE-2023-47637Pimcore sql injection vulnerabilityPimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterConditi…EPSS 1.2%8.8CVE-2023-38708Pimcore path traversal vulnerabilityPimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist…EPSS 0.64%8.8CVE-2023-2983Pimcore vulnerabilityPrivilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.EPSS 0.92%8.8CVE-2023-2984Pimcore vulnerabilityPath Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2022-0832), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.