Vulnerabilities > Supsystic > Popup > 1.2.3

DATE CVE VULNERABILITY TITLE RISK
2024-12-13 CVE-2023-39997 Missing Authorization vulnerability in Supsystic Popup
Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.
network
low complexity
supsystic CWE-862
critical
9.8
2024-12-09 CVE-2023-51353 Unspecified vulnerability in Supsystic Popup
Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.
network
low complexity
supsystic
critical
9.8
2024-11-18 CVE-2024-52434 Code Injection vulnerability in Supsystic Popup
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
network
low complexity
supsystic CWE-94
critical
9.1
2024-05-17 CVE-2023-46197 Unspecified vulnerability in Supsystic Popup
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
network
low complexity
supsystic
6.5
2024-04-15 CVE-2024-31421 Unspecified vulnerability in Supsystic Popup
Missing Authorization vulnerability in Supsystic Popup by Supsystic.This issue affects Popup by Supsystic: from n/a through 1.10.27.
network
low complexity
supsystic
4.3
2023-07-17 CVE-2023-3186 Unspecified vulnerability in Supsystic Popup
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
network
low complexity
supsystic
critical
9.8
2022-05-09 CVE-2022-0424 Unspecified vulnerability in Supsystic Popup
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
network
low complexity
supsystic
5.3
2021-05-05 CVE-2021-24275 Unspecified vulnerability in Supsystic Popup
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
network
low complexity
supsystic
6.1
2019-08-20 CVE-2016-10915 Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Popup
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
network
low complexity
supsystic CWE-352
8.8