← Vulnerability feed

Vulnerability record · CVE-2023-1578 · published 22 March 2023

CVE-2023-1578: Pimcore SQL injection before 10.5.19

Pimcore · Pimcore

Pimcore versions prior to 10.5.19 contain a SQL injection flaw (CWE-89) in the GitHub repository pimcore/pimcore. A low-privileged authenticated user can inject SQL through a network-reachable interface, which matters because it can compromise the confidentiality, integrity and availability of the underlying database.

8.8 CVSS 3.1 High EPSS 63% · top 0.8% CWE-89 · SQL injection
8.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with high EPSS and a public exploit reference, though exploitation requires an authenticated low-privileged account.

What it is

Pimcore versions prior to 10.5.19 contain a SQL injection flaw (CWE-89) in the GitHub repository pimcore/pimcore. A low-privileged authenticated user can inject SQL through a network-reachable interface, which matters because it can compromise the confidentiality, integrity and availability of the underlying database.

Impact

An attacker with a low-privileged account can read, modify or delete database contents and potentially disrupt the application, given the high confidentiality, integrity and availability impact in the CVSS vector.

Attack surface

Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires a low-privileged authenticated account (PR:L).

Exploitation

Not listed in CISA KEV, but EPSS is 0.62755 (99.157th percentile) and the references include an Exploit-tagged third-party advisory, indicating public exploit information exists.

What to do

  • Upgrade Pimcore to 10.5.19 or later, applying the patch commit 367b74488808d71ec3f66f4ca9e8df5217c2c8d2.
  • Restrict network access to Pimcore administrative and application interfaces to trusted users.
  • Review and minimize accounts with low-privileged access, and enforce least privilege.
  • Audit database accounts used by Pimcore and remove unnecessary write or DDL permissions.

Detection

  • Monitor database and application logs for SQL syntax errors or anomalous query patterns from authenticated sessions.
  • Alert on unexpected bulk reads, writes or schema changes originating from Pimcore application accounts.
  • Review access logs for unusual authenticated activity against Pimcore endpoints that handle user-supplied input.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1578 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-39365Pimcore code injection vulnerabilityPimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/…EPSS 1.8%9.8CVE-2019-18981Pimcore vulnerabilityPimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.EPSS 1.4%9.8CVE-2019-18985Pimcore improper restriction of authentication attempts vulnerabilityPimcore before 6.2.2 lacks brute force protection for the 2FA token.EPSS 1.4%9.0CVE-2021-4139Pimcore cross-site scripting vulnerabilitypimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.88%8.8CVE-2023-47637Pimcore sql injection vulnerabilityPimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterConditi…EPSS 1.2%8.8CVE-2023-38708Pimcore path traversal vulnerabilityPimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist…EPSS 0.64%8.8CVE-2023-2983Pimcore vulnerabilityPrivilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.EPSS 0.92%8.8CVE-2023-2984Pimcore vulnerabilityPath Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2023-1578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.