Skip to content

Pimcore

v12.3.9 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cdp cms cms-framework customer-data-platform dam data-management
+13 more
digital-platform ecommerce ecommerce-platform experience-manager master-data-management mdm online-shop pim pimcore product-information-management product-management shop wcms

ReleasePort's take

Moderate signal
editorial:auto 1mo

The release adds a regex check and quoting to block table injection attacks in Dependency Dao query handling.

Why it matters: A severity‑90 security fix blocks table injection attacks via regex validation; critical for any system using Dependency Dao queries.

Summary

AI summary

Fixed Symfony Scheduler commands not being usable (PEES-1043).

Changes in this release

Security Critical

Adds regex check and quoting to block table injection attacks

Adds regex check and quoting to block table injection attacks

Source: llm_adapter@2026-06-09

Confidence: high

Feature Low

Adds DependencyTargetsChangedMessage to Dependency Dao

Adds DependencyTargetsChangedMessage to Dependency Dao

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Adds missing check for assets->image->thumbnails->status_cache configuration option

Adds missing check for assets->image->thumbnails->status_cache configuration option

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Fixes Symfony Scheduler commands becoming unusable

Fixes Symfony Scheduler commands becoming unusable

Source: llm_adapter@2026-06-09

Confidence: low

Bugfix Low

Fixes statistics issue in Studio

Fixes statistics issue in Studio

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

What's Changed

  • [Task]: Add DependencyTargetsChangedMessage to Dependency Dao by @martineiber in https://github.com/pimcore/pimcore/pull/19156
  • [Bug, EC] PEES-1043: Symfony Scheduler - Commands not usable by @robertSt7 in https://github.com/pimcore/pimcore/pull/19170
  • [Bug]: Missing check if config "assets->image->thumbnails->status_cache" option is enabled/disabled by @kingjia90 in https://github.com/pimcore/pimcore/pull/19174
  • [Security]: Follow up regex check and add quoting to block tables by @kingjia90 in https://github.com/pimcore/pimcore/pull/19177
  • Statistics: fix for Studio by @brusch in https://github.com/pimcore/pimcore/pull/19115
  • DataObject\Listing: Add missing PhpDocs by @blankse in https://github.com/pimcore/pimcore/pull/18844

Full Changelog: https://github.com/pimcore/pimcore/compare/v12.3.8...v12.3.9

Security Fixes

  • Regex check with quoting added to block tables — security hardening.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pimcore

Get notified when new releases ship.

Sign up free

About Pimcore

Multi-channel experience and engagement management platform.

All releases →

Related context

Beta — feedback welcome: [email protected]