aimeos
Web & CMS Pluginsoss-project
Latest CVEs
The 13 most recently published vulnerabilities affecting aimeos.
- CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy3.0
- CVE-2021-47763Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection8.2
- CVE-2025-66468Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors7.6
- CVE-2024-47173Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups5.5
- CVE-2024-39319aimeos/ai-controller-frontend has IDOR vulnerability in account profile page5.3
- CVE-2024-39325aimeos/ai-controller-frontend doesn't reset payment status in basket5.3
- CVE-2024-39322aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required records5.5
- CVE-2024-39324aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services3.8
- CVE-2024-39323aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account7.1
- CVE-2024-38516Aimeos HTML client may potentially reveal sensitive information in error log8.8
- CVE-2024-37296Aimeos HTML client vulnerable to digital products download without proper payment status check5.3
- CVE-2024-37295Aimeos Core remote code execution in web server context7.2
- CVE-2024-37294Aimeos denial of service vulnerability in SaaS and marketplace setups5.5