Pineapple Technologies maintains a focused product portfolio centered on educational and quiz-oriented applications, with its vulnerability footprint concentrated in web application input handling. The recurring signal points to cross-site scripting weaknesses across products such as Lore and QuizShock, reflecting the common challenges of web-facing educational platforms. Current severity, exploitation, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pineapple Technologies over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3988HIGH SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 4, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-2021HIGH Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to | Apr 12, 2007 | 7.5 | 25 | NO | NO |
CVE-2007-1905MEDIUM Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encode | Apr 10, 2007 | 4.3 | 22 | NO | YES |
CVE-2006-2836HIGH SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | Jun 6, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pineapple Technologies.
Media articles that mention a CVE ID that affects a product developed by Pineapple Technologies — matched by CVE ID, not by vendor name.