Vulnerabilities > Supsystic > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-18 CVE-2024-52434 Code Injection vulnerability in Supsystic Popup
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
network
low complexity
supsystic CWE-94
critical
9.1
2023-07-17 CVE-2023-3186 Unspecified vulnerability in Supsystic Popup
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
network
low complexity
supsystic
critical
9.8