CVE-2018-1000546: Triplea-Game Triplea

High severity, CVSS 7.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).

Affected products

Published 2018-06-26. Last modified 2026-06-17.