VYPR

Popup by Supsystic

by Supsystic

CVEs (9)

  • CVE-2024-52434CriNov 18, 2024
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

  • CVE-2023-46197MedMay 17, 2024
    risk 0.36cvss 5.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

  • CVE-2023-39997MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.

  • CVE-2023-51353MedDec 9, 2024
    risk 0.34cvss 5.3epss 0.01

    Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19.

  • CVE-2024-31421MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.

  • CVE-2022-0424May 9, 2022
    risk 0.03cvss epss 0.03

    The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

  • CVE-2021-24275May 5, 2021
    risk 0.03cvss epss 0.18

    The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

  • CVE-2023-3186Jul 17, 2023
    risk 0.00cvss epss 0.01

    The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

  • CVE-2016-10915Aug 20, 2019
    risk 0.00cvss epss 0.01

    The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.