Pimcore prior to 10.4.0 is vulnerable to stored cross-site scripting. References https://nvd.nist.gov/vuln/detail/CVE-2022-0894 https://github.com/pimcore/pimcore/commit/6e0922c5b2959ac1b48500ac508d8fc5a97286f9 https://huntr.dev/bounties/18f8e85e-3cbf-4915-b649-8cffe99daa95 https://github.com/pimcore/pimcore/pull/11447 https://github.com/advisories/GHSA-22hc-47cc-7x6f