CVE-2026-5362
EUVD-2026-2591727.04.2026, 21:16
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pimcore | pimcore | 12.3.3 |
𝑥
= Vulnerable software versions