[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-55634":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-28T22:53:37.900Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":93,"aliases":94,"duplicate_of":9,"upstream":95,"downstream":96,"duplicates":97,"related":98,"reserved_at":9,"published_at":99,"modified_at":100,"state":101,"summary":102,"references_raw":109,"kevs":133,"epss":9,"epss_history":134,"metrics":135,"affected":143},"CVE-2026-55634","Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and by models/DataObject/ClassDefinition/Helper/Dao.php into ALTER TABLE identifiers. An authenticated user with the objects permission can inject PHP syntax into the generated DataObject class, causing attacker-controlled code in generated var/classes/DataObject/.php files to run when an object of that class is instantiated, and can also inject SQL identifier content into schema-changing statements. The central models/DataObject/ClassDefinition/Data.php::setName() validation did not reject semicolons, braces, backticks, spaces, or other non-identifier characters. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.",null,[11,44],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-89","Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.","weakness","Stable","Base","High",[20,24,28,32,36,40],{"id":21,"name":22,"techniques":23},"CAPEC-108","Command Line Execution through SQL Injection",[],{"id":25,"name":26,"techniques":27},"CAPEC-109","Object Relational Mapping Injection",[],{"id":29,"name":30,"techniques":31},"CAPEC-110","SQL Injection through SOAP Parameter Tampering",[],{"id":33,"name":34,"techniques":35},"CAPEC-470","Expanding Control over the Operating System from the Database",[],{"id":37,"name":38,"techniques":39},"CAPEC-66","SQL Injection",[],{"id":41,"name":42,"techniques":43},"CAPEC-7","Blind SQL Injection",[],{"_key":45,"id":45,"name":46,"description":47,"type":15,"status":48,"abstraction":17,"likelihood_of_exploit":49,"capec":50},"CWE-94","Improper Control of Generation of Code ('Code Injection')","The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.","Draft","Medium",[51,55,89],{"id":52,"name":53,"techniques":54},"CAPEC-242","Code Injection",[],{"id":56,"name":57,"techniques":58},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[59,70,77],{"id":60,"name":61,"tactics":62,"countermeasures":69},"T1027.006","HTML Smuggling",[63,66],{"id":64,"name":65},"TA0030","Defense Evasion",{"id":67,"name":68},"TA0005","Stealth",[],{"id":71,"name":72,"tactics":73,"countermeasures":76},"T1027.009","Embedded Payloads",[74,75],{"id":64,"name":65},{"id":67,"name":68},[],{"id":78,"name":79,"tactics":80,"countermeasures":83},"T1564.009","Resource Forking",[81,82],{"id":64,"name":65},{"id":67,"name":68},[84],{"id":85,"name":86,"tactic":87},"D3-FFV","File Format Verification",{"name":88},"Isolate",{"id":90,"name":91,"techniques":92},"CAPEC-77","Manipulating User-Controlled Variables",[],[],[],[],[],[],[],"2026-08-28T19:16:20.078Z","2026-08-28T20:06:15.024Z","Received",{"cisa_kev":103,"cisa_ransomware":103,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":104,"severity_score":105,"severity_version":106,"severity_source":107,"severity_vector":108,"severity_status":101},false,"critical",9.9,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",[110,116,121,125,129],{"url":111,"sources":112,"tags":114},"https://github.com/pimcore/pimcore/security/advisories/GHSA-9x44-4gxf-8c25",[107,113],"nvd",[115],"X Refsource CONFIRM",{"url":117,"sources":118,"tags":119},"https://github.com/pimcore/pimcore/pull/19183",[107,113],[120],"X Refsource MISC",{"url":122,"sources":123,"tags":124},"https://github.com/pimcore/pimcore/commit/a4f8c3cfee58b7d5fe4873d67782eff58dae9b9d",[107,113],[120],{"url":126,"sources":127,"tags":128},"https://github.com/advisories/GHSA-r2f4-ff2p-xc64",[107,113],[120],{"url":130,"sources":131,"tags":132},"https://github.com/pimcore/pimcore/releases/tag/v2026.1.6",[107,113],[120],[],[],[136,141],{"source":107,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":137,"cvss_v4_0":9},{"baseScore":105,"baseSeverity":138,"vectorString":108,"impactScore":139,"exploitabilityScore":140},"CRITICAL",10,7.9,{"source":113,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":142,"cvss_v4_0":9},{"baseScore":105,"baseSeverity":138,"vectorString":108,"impactScore":139,"exploitabilityScore":140},[144],{"ecosystem":9,"name":145,"vendor":145,"product":145,"cpe_part":146,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":147},"pimcore","a",[148,153,158],{"version":149,"is_range":150,"range_type":107,"version_start":9,"version_start_type":9,"version_end":151,"version_end_type":152,"fixed_in":9},"\u003C 11.5.19",true,"11.5.19","excluding",{"version":154,"is_range":150,"range_type":107,"version_start":155,"version_start_type":156,"version_end":157,"version_end_type":152,"fixed_in":9},">= 12.0.0-RC1, \u003C 12.3.10","12.0.0-RC1","including","12.3.10",{"version":159,"is_range":150,"range_type":107,"version_start":160,"version_start_type":156,"version_end":161,"version_end_type":152,"fixed_in":9},">= 2026.1.0, \u003C 2026.1.6","2026.1.0","2026.1.6"]