PT-2025-1723 · Pimcore · Pimcore

·

CVE-2024-11954

·

Published

2025-01-28

·

Updated

2025-11-04

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Pimcore version 11.4.2
Description A problematic issue was found in the Search Document component, leading to basic cross site scripting. The manipulation can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations Pimcore version 11.4.2: Update to a version that fixes the issue in the Search Document component to prevent basic cross site scripting.

Exploit

Fix

XSS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07528
CVE-2024-11954
GHSA-8M2R-X2M2-3WMW
GHSA-XR3M-6GQ6-22CG

Affected Products

Pimcore