<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Akeneo PIM (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/akeneo-pim.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/akeneo-pim-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Akeneo PIM (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2022-46157 – Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46157</guid>
    <pubDate>Fri, 09 Dec 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46157</strong></p>
  <p>Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the versions aforementioned provides patched Apache HTTP server configuration file, for docker setup and in documentation s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000009 – Akeneo PIM CE and EE &lt;1.6.6, &lt;1.5.15, &lt;1.4.28 are vulnerable to shell injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000009</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000009</strong></p>
  <p>Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000009">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
