Skip to main content

Vendor/product archive

supsystic / popup CVEs

Beta · best-effort

10 CVEs tagged to supsystic / popup2 Critical, 1 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2023-39997

Published Dec 13, 2024

Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsyst…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-51353

Published Dec 9, 2024

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects P…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52434

Published Nov 18, 2024

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46197

Published May 17, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-31421

Published Apr 15, 2024

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3186

Published Jul 17, 2023

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-20065

Published Jun 20, 2022

A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0424

Published May 9, 2022

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24275

Published May 5, 2021

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1