SecBoard
Zurück zur CVE-Übersicht

CVE-2026-5362

MEDIUM(5.4)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Risk Signal Score14/100 — NIEDRIG
  • CVSS 5.4 — Mittel

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

5.4

Technische Schwere

Beschreibung

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

GitHub Advisories

GHSA-7gxw-q9j5-mrj4MEDIUM

Pimcore has an authenticated Cross-site Scripting issue

composer/pimcore/pimcore
GitHub Advisory

Referenzen