CVE-2026-22242

MEDIUM

Coreshop < 4.1.8 - SQL Injection

Title source: rule
STIX 2.1

Description

CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8.

Scores

CVSS v3 4.9
EPSS 0.0001
EPSS Percentile 2.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-564 CWE-89
Status published
Products (2)
coreshop/core-shop 0 - 4.1.8Packagist
coreshop/coreshop < 4.1.8
Published Jan 08, 2026
Tracked Since Feb 18, 2026