GHSA-q8cr-xphm-7gfv · Severity: critical · Ecosystem: composer — Akeneo PIM vulnerable to shell injection in the mass edition
Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
Conclusion & alert: CVE-2017-1000009 is rated High Risk (71.2/100): CVSS Critical severity, with high exploitation likelihood (EPSS 10.46%, 93th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-16 | 11.10% | 10.46% | -0.64% |
| 2 | 2025-03-30 | 9.96% | 11.10% | +1.13% |
| 3 | 2025-03-29 | — | 9.96% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-q8cr-xphm-7gfv · Severity: critical · Ecosystem: composer — Akeneo PIM vulnerable to shell injection in the mass edition
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:-:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta2:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta3:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:rc1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.1 | cpe:2.3:a:akeneo:product_information_management:1.4.1:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.2 | cpe:2.3:a:akeneo:product_information_management:1.4.2:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.3 | cpe:2.3:a:akeneo:product_information_management:1.4.3:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.4 | cpe:2.3:a:akeneo:product_information_management:1.4.4:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.5 | cpe:2.3:a:akeneo:product_information_management:1.4.5:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.6 | cpe:2.3:a:akeneo:product_information_management:1.4.6:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.7 | cpe:2.3:a:akeneo:product_information_management:1.4.7:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.8 | cpe:2.3:a:akeneo:product_information_management:1.4.8:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.9 | cpe:2.3:a:akeneo:product_information_management:1.4.9:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.10 | cpe:2.3:a:akeneo:product_information_management:1.4.10:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.11 | cpe:2.3:a:akeneo:product_information_management:1.4.11:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.12 | cpe:2.3:a:akeneo:product_information_management:1.4.12:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.13 | cpe:2.3:a:akeneo:product_information_management:1.4.13:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.14 | cpe:2.3:a:akeneo:product_information_management:1.4.14:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.15 | cpe:2.3:a:akeneo:product_information_management:1.4.15:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.16 | cpe:2.3:a:akeneo:product_information_management:1.4.16:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.17 | cpe:2.3:a:akeneo:product_information_management:1.4.17:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.18 | cpe:2.3:a:akeneo:product_information_management:1.4.18:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.19 | cpe:2.3:a:akeneo:product_information_management:1.4.19:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.20 | cpe:2.3:a:akeneo:product_information_management:1.4.20:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.21 | cpe:2.3:a:akeneo:product_information_management:1.4.21:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.22 | cpe:2.3:a:akeneo:product_information_management:1.4.22:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.23 | cpe:2.3:a:akeneo:product_information_management:1.4.23:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.24 | cpe:2.3:a:akeneo:product_information_management:1.4.24:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.25 | cpe:2.3:a:akeneo:product_information_management:1.4.25:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.26 | cpe:2.3:a:akeneo:product_information_management:1.4.26:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.27 | cpe:2.3:a:akeneo:product_information_management:1.4.27:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.0 | cpe:2.3:a:akeneo:product_information_management:1.5.0:-:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.0 | cpe:2.3:a:akeneo:product_information_management:1.5.0:alpha1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.0 | cpe:2.3:a:akeneo:product_information_management:1.5.0:beta1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.0 | cpe:2.3:a:akeneo:product_information_management:1.5.0:rc1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.1 | cpe:2.3:a:akeneo:product_information_management:1.5.1:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.2 | cpe:2.3:a:akeneo:product_information_management:1.5.2:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.3 | cpe:2.3:a:akeneo:product_information_management:1.5.3:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.4 | cpe:2.3:a:akeneo:product_information_management:1.5.4:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.5 | cpe:2.3:a:akeneo:product_information_management:1.5.5:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.6 | cpe:2.3:a:akeneo:product_information_management:1.5.6:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.7 | cpe:2.3:a:akeneo:product_information_management:1.5.7:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.8 | cpe:2.3:a:akeneo:product_information_management:1.5.8:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.9 | cpe:2.3:a:akeneo:product_information_management:1.5.9:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.10 | cpe:2.3:a:akeneo:product_information_management:1.5.10:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.11 | cpe:2.3:a:akeneo:product_information_management:1.5.11:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.12 | cpe:2.3:a:akeneo:product_information_management:1.5.12:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.13 | cpe:2.3:a:akeneo:product_information_management:1.5.13:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.5.14 | cpe:2.3:a:akeneo:product_information_management:1.5.14:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.0 | cpe:2.3:a:akeneo:product_information_management:1.6.0:-:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.0 | cpe:2.3:a:akeneo:product_information_management:1.6.0:alpha1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.0 | cpe:2.3:a:akeneo:product_information_management:1.6.0:alpha2:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.0 | cpe:2.3:a:akeneo:product_information_management:1.6.0:rc1:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.1 | cpe:2.3:a:akeneo:product_information_management:1.6.1:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.2 | cpe:2.3:a:akeneo:product_information_management:1.6.2:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.3 | cpe:2.3:a:akeneo:product_information_management:1.6.3:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.4 | cpe:2.3:a:akeneo:product_information_management:1.6.4:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.6.5 | cpe:2.3:a:akeneo:product_information_management:1.6.5:*:*:*:enterprise:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:-:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta1:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta2:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:beta3:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.0 | cpe:2.3:a:akeneo:product_information_management:1.4.0:rc1:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.1 | cpe:2.3:a:akeneo:product_information_management:1.4.1:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.2 | cpe:2.3:a:akeneo:product_information_management:1.4.2:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.3 | cpe:2.3:a:akeneo:product_information_management:1.4.3:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.4 | cpe:2.3:a:akeneo:product_information_management:1.4.4:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.5 | cpe:2.3:a:akeneo:product_information_management:1.4.5:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.6 | cpe:2.3:a:akeneo:product_information_management:1.4.6:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.7 | cpe:2.3:a:akeneo:product_information_management:1.4.7:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.8 | cpe:2.3:a:akeneo:product_information_management:1.4.8:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.9 | cpe:2.3:a:akeneo:product_information_management:1.4.9:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.10 | cpe:2.3:a:akeneo:product_information_management:1.4.10:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.11 | cpe:2.3:a:akeneo:product_information_management:1.4.11:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.12 | cpe:2.3:a:akeneo:product_information_management:1.4.12:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.13 | cpe:2.3:a:akeneo:product_information_management:1.4.13:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.14 | cpe:2.3:a:akeneo:product_information_management:1.4.14:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.15 | cpe:2.3:a:akeneo:product_information_management:1.4.15:*:*:*:community:*:*:* |
| akeneo | product_information_management | 1.4.16 | cpe:2.3:a:akeneo:product_information_management:1.4.16:*:*:*:community:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2 | Patch Release Notes Third Party Advisory |
| https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes | Patch Release Notes Third Party Advisory |
| https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2 | Patch Release Notes Third Party Advisory |