coreshop CVE 脆弱性と CVE 一覧(2)

製品(CPE): — CVE 件数: 2

coreshop 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to coreshop, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 12 / 2 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-23959 CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` within the CoreShop admin panel. The affected endpoint improperly interpolates user-supplied input into a SQL query, leading to database error disclosure and potential data extraction. Version 4.1.9 fixes the issue. [email protected] 6.9 0.01% 2026-01-22 2026-02-17
CVE-2026-22242 CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8. [email protected] 4.9 0.02% 2026-01-08 2026-01-12
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence