robertSt7
17 exploits
Active since Jan 2023
Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVSS 7.2
pimcore customer_management_framework < 4.0.6 - Authenticated Improper Access Control in Duplicates Endpoint
CVSS 6.5
pimcore < 10.5.14 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.21 - Path Traversal
CVSS 6.5
pimcore < 10.5.21 - Reflected Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.21 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.21 - DOM-Based Cross-Site Scripting
CVSS 5.4
pimcore < 10.5.21 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.6.4 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
pimcore < 10.6.8 - Reflected Cross-Site Scripting
CVSS 5.4
Pimcore Admin Classic Bundle <1.2.0 - XSS
CVSS 6.1
Pimcore Admin Classic Bundle <1.2.0 - XSS
CVSS 6.1
pimcore < 11.1.1 - Authenticated SQL Injection via Grid Proxy Endpoint
CVSS 8.8
pimcore < 11.1.0 - Stored Cross-Site Scripting
CVSS 5.4
Pimcore <1.3.3 - Privilege Escalation
CVSS 6.5
Pimcore Admin Classic Bundle <1.3.10/1.4.6/1.5.2 - Sensitive Information Exposure
CVSS 6.3
pimcore admin_classic_bundle < 1.7.6 - HTML Injection via Email Content Parameter
CVSS 4.8