« Back to list

Pippo

Pippo: vulnerabilities and CVEs

Pippo has 6 published vulnerabilities, 1 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months1
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-69037High (8.1)0.47%—Jan 22, 2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Pippo pippo allows PHP Local File Inclusion.This issue affects Pippo: from n/a through…
CVE-2019-5442High (7.5)1.4%—Jun 12, 2019
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory.…
CVE-2018-20059Critical (9.8)1.5%—Dec 11, 2018
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
CVE-2018-18628Critical (9.8)5.5%—Oct 23, 2018
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker…
CVE-2017-18349Critical (9.8)39%—Oct 23, 2018
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI…
CVE-2018-18240Critical (9.8)3.7%—Oct 11, 2018
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.