Popup by Supsystic
by WordPress
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73380 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | ||
| CVE-2023-3186 | Cri | 0.64 | 9.8 | 0.01 | Jul 17, 2023 | The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype. | ||
| CVE-2026-73381 | Cri | 0.59 | 9.1 | 0.01 | Aug 18, 2026 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||
| CVE-2024-52434 | Cri | 0.59 | 9.1 | 0.01 | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29. | ||
| CVE-2016-10915 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. | ||
| CVE-2021-24275 | Med | 0.44 | 6.1 | 0.18 | May 5, 2021 | The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | ||
| CVE-2026-27537 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||
| CVE-2023-46197 | Med | 0.35 | 5.3 | 0.01 | May 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19. | ||
| CVE-2022-0424 | Med | 0.35 | 5.3 | 0.03 | May 9, 2022 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users | ||
| CVE-2023-39997 | Med | 0.34 | 5.3 | 0.01 | Dec 13, 2024 | Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19. | ||
| CVE-2023-51353 | Med | 0.34 | 5.3 | 0.01 | Dec 9, 2024 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19. | ||
| CVE-2024-31421 | Med | 0.28 | 4.3 | 0.00 | Apr 15, 2024 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27. |
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- risk 0.64cvss 9.8epss 0.01
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
- risk 0.59cvss 9.1epss 0.01
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
- risk 0.59cvss 9.1epss 0.01
Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
- risk 0.57cvss 8.8epss 0.01
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
- risk 0.44cvss 6.1epss 0.18
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
- risk 0.35cvss 5.3epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
- risk 0.35cvss 5.3epss 0.03
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
- risk 0.34cvss 5.3epss 0.01
Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.
- risk 0.34cvss 5.3epss 0.01
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19.
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.