E-Commerce
pimcore/pimcore
Core Framework for the Open Core Data & Experience Management Platform (PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce)
#pimcore#cms#pim#shop#ecommerce#ecommerce-platform#master-data-management#dam#wcms#digital-platform#experience-manager#data-management#product-management#product-information-management#cms-framework#mdm#online-shop#cdp#customer-data-platform#hacktoberfest
スコア
80
/ 100
Star
3,755
Fork
1,505
Open Issue
501
サイズ
530MB
言語
PHP ★
最終push
0 日前
Docker
—
採点内訳
過去CVE 17件 (やや多い)
✓直近 push: 1 日前
✓得意言語 (PHP)
✓オープンissue 501件
✓超大規模 (0.5GB)
—Docker 未対応
—1k–10k: 初心者ベスト (★3,755)
✓※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (20 件)
- SQL injection via unsanitized filter value in Dependency Dao RLIKE clause
- Broken Access Control: "Favourite Output Channel Configuration" Missing Function Level Authorization
- Broken Access Control: Missing Function Level Authorization on "Static Routes" Listing
- Broken Access Control: Missing Function Level Authorization on "Predefined Properties" Listing
- ENV Variables and Cookie Informations exposed in http_error_log
- (Incomplete Patch )[Blind SQL Injection] in Admin Search Find API
- SQL Injections in getRelationFilterCondition
- Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
- SQL Injection: Hibernate in NA
- Change-Password via Portal-Profile sets PimcoreBackendUser password without hashing
- CVE-2024-45048 PHPOffice/PhpSpreadsheet
- Flooding Server with Thumbnail files
- Pimcore TinyMCE Bundle - tinymce CVE-2024-29203, CVE-2024-29881
- Pimcore Preview Documents are not restricted to logged in users anymore
- SQL Injection in Admin Grid Filter API through Multiselect::getFilterConditionExt()
- Cross-site Scripting (XSS) in DataObject datetime fields
- Path traversal in AssetController:importServerFilesAction
- SQL Injection in Dataobjects sorting
- Exposure of Sensitive Information to an Unauthorized Actor
- Pre-Auth Path traversal in pimcore_log parameter