Pineapp develops a focused line of email security appliances centered on its Mail Secure product family, which operates at the messaging perimeter of organizations. The vulnerability footprint is concentrated in these gateway devices and characterized by web-facing and authentication-related weakness classes including code injection, path traversal, cross-site scripting, and improper authentication that are typical of appliance management interfaces and email-processing logic. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pineapp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6829HIGH admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation. | Nov 20, 2013 | 7.5 | 82 | NO | YES |
CVE-2013-6830HIGH admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in | Nov 20, 2013 | 7.5 | 37 | NO | YES |
CVE-2013-4987HIGH PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command. | Nov 8, 2013 | 8.5 | 31 | NO | YES |
CVE-2013-6831HIGH PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privil | Nov 20, 2013 | 7.2 | 27 | NO | YES |
CVE-2021-36720MEDIUM PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies . | Dec 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2013-6828MEDIUM admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter. | Nov 20, 2013 | 6.4 | 17 | NO | NO |
CVE-2013-6827MEDIUM Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter. | Nov 20, 2013 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pineapp.
Media articles that mention a CVE ID that affects a product developed by Pineapp — matched by CVE ID, not by vendor name.