Vulnerabilities > Supsystic > Low

DATE CVE VULNERABILITY TITLE RISK
2022-07-17 CVE-2022-2114 Cross-site Scripting vulnerability in Supsystic Data Tables Generator
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
network
supsystic CWE-79
3.5
2021-11-01 CVE-2021-39346 Cross-site Scripting vulnerability in Supsystic Easy Google Maps
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33.
network
high complexity
supsystic CWE-79
2.1