CVE-2018-14057: Pimcore

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

Affected products

  • Pimcore Pimcore: before 5.3.0 (fixed in 5.3.0)

Published 2018-08-17. Last modified 2026-06-17.