This is exactly the class of bug that manual testing misses: it does not fail with an error; it simply does not work as it should. ### GHSA-mvh8-52hw-jrch: A CVE-Class Patch In 2026.2.12, GHSA-mvh8-52hw-jrch was also fixed by escaping embedded YouTube and Dailymotion players. This is an XSS-class vulnerability: unescaped embed code in a CMS gives an attacker a way to inject a script into someone else's page.
Patches Are Coming, but No New Feature Announcements
-
Pimcore released four patches in succession within one week - 2026.2.4, 2026.2.10, 2026.2.11, and 2026.2.12.
-
Not one of them is headline material for a marketing announcement: no new modules, no Pimcore Studio redesign.
-
But these patches are exactly what show whether you are dealing with a mature DAM/PIM platform or merely a showcase.
-
The developers fixed a file leak when moving an asset folder, closed XSS vulnerabilities in embed players, and stopped the uncontrolled growth of service log tables.
-
For a business storing a product catalog or media library in Pimcore, this is not cosmetic - it determines whether you lose customer data.


