CVE-2026-44741: Pimcore
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation. Versiosn 2.3.6 and 1.7.18 fix the issue.
Affected products
- Pimcore Pimcore: before 1.7.18 (fixed in 1.7.18); from 2.0.0-RC1, before 2.3.6 (fixed in 2.3.6)
Published 2026-08-12. Last modified 2026-09-16.