Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Putzflorian

#30532of 53,633
8.6Total CVSS
Vulnerabilities · 1
PT-2026-3074
8.6
2026-01-15
Pimcore · Pimcore · CVE-2026-23493
**Name of the Vulnerable Software and Affected Versions** Pimcore versions prior to 12.3.1 Pimcore versions prior to 11.5.14 **Description** Pimcore is an Open Source Data & Experience Management Platform. Prior to versions 12.3.1 and 11.5.14, the `http error log` file stores the `$ COOKIE` and `$ SERVER` variables. This can lead to the exposure of sensitive information, including database passwords and cookie session data, accessible through the Pimcore backend. **Recommendations** Versions prior to 12.3.1 should be updated to version 12.3.1 or later. Versions prior to 11.5.14 should be updated to version 11.5.14 or later.