CVE-2026-5362
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.
MEDIUM · CVSS 5.4
EPSS 4e-05
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0