Record summary

CVE-2026-44741 has a selected CVSS score of 8.8 (high).

Description

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation. Versiosn 2.3.6 and 1.7.18 fix the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 1.7.18affected
>= 2.0.0-RC1, < 2.3.6affected
GitHub Advisory2.0.0-RC1 to < 2.3.6 · Fixed in 2.3.6affected
Before 1.7.18 · Fixed in 1.7.18affected

References

5