THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-44741 (HIGH 8.8) — Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMEST

[NVD] CVE-2026-44741 (HIGH 8.8) — Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMEST

lownvdPublished 2026-08-12

CVE-2026-44741 CVSS: 8.8 HIGH Published: 2026-08-12T18:17:29.823

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44741