Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Popup CRITICAL 9.8
CVE-2023-39997

Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Fix: 1.10.20+
Fix from $2,300 2024-12-13
Popup CRITICAL 9.8
CVE-2023-51353

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Securi…

Fix: 1.10.20+
Fix from $2,300 2024-12-09
Popup CRITICAL 9.1
CVE-2024-52434

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup …

Fix: after 1.10.29
Fix from $2,300 2024-11-18
Slider HIGH 8.8
CVE-2024-47330

Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsys…

Fix: 1.8.7+
Fix from $1,950 2024-09-26
Easy Google Maps MEDIUM 5.4
CVE-2024-5219

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, an…

Fix: 1.11.16+
Fix from $1,600 2024-07-02
Popup MEDIUM 6.5
CVE-2023-46197

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path…

Fix: 1.10.20+
Fix from $1,600 2024-05-17
Easy Google Maps HIGH 8.8
CVE-2024-31269

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.

Fix: 1.11.12+
Fix from $1,950 2024-04-12
Digital Publications By Supsystic HIGH 8.8
CVE-2023-5756

The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This …

Fix: after 1.7.6
Fix from $1,950 2023-12-09
Contact Form HIGH 8.8
CVE-2023-45068

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions.

Fix: after 1.7.27
Fix from $1,950 2023-10-12
Popup CRITICAL 9.8
CVE-2023-3186

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary prope…

Fix: 1.10.19+
Fix from $2,300 2023-07-17
Easy Google Maps MEDIUM 5.4
CVE-2023-2526

The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missin…

Fix: after 1.11.7
Fix from $1,600 2023-06-09
Easy Google Maps HIGH 8.8
CVE-2023-33926

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.

Fix: 1.11.8+
Fix from $1,950 2023-05-28
Coming Soon HIGH 8.8
CVE-2023-22714

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions.

Fix: after 1.7.10
Fix from $1,950 2023-05-22
Contact Form HIGH 8.8
CVE-2023-2528

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due …

Fix: after 1.7.24
Fix from $1,950 2023-05-17
Slider HIGH 8.8
CVE-2022-47155

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions.

Fix: after 1.8.5
Fix from $1,950 2023-03-14
Social Share Buttons HIGH 8.8
CVE-2022-27235

Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

Fix: 2.2.4+
Fix from $1,950 2022-07-22
Social Share Buttons HIGH 8.8
CVE-2022-33960

Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at …

Fix: 2.2.4+
Fix from $1,950 2022-07-22
Popup MEDIUM 5.3
CVE-2022-0424

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated …

Fix: 1.10.9+
Fix from $1,600 2022-05-09
Easy Google Maps MEDIUM 6.1
CVE-2021-46780

The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboar…

Fix: 1.9.32+
Fix from $1,600 2022-04-25
Price Table MEDIUM 6.1
CVE-2021-46782

The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin…

Fix: 1.9.5+
Fix from $1,600 2022-04-25
Ultimate Maps MEDIUM 6.1
CVE-2021-24274EPSS 18%

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attrib…

Fix: 1.2.5+
Fix from $1,600 2021-05-05
Popup MEDIUM 6.1
CVE-2021-24275EPSS 18%

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, le…

Fix: 1.10.5+
Fix from $1,600 2021-05-05
Contact Form MEDIUM 6.1
CVE-2021-24276EPSS 16%

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attrib…

Fix: 1.7.15+
Fix from $1,600 2021-05-05
Data Tables Generator HIGH 8.8
CVE-2020-12075

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

Fix: 1.9.92+
Fix from $1,950 2020-04-23
Data Tables Generator HIGH 8.8
CVE-2020-12076

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored…

Fix: 1.9.92+
Fix from $1,950 2020-04-23
Pricing Table By Supsystic HIGH 7.3
CVE-2020-9392

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTa…

Fix: 1.8.2+
Fix from $1,950 2020-03-23
Pricing Table By Supsystic HIGH 8.8
CVE-2020-9394

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

Fix: 1.8.2+
Fix from $1,950 2020-02-25
Pricing Table By Supsystic MEDIUM 6.1
CVE-2020-9393

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.

Fix: 1.8.2+
Fix from $1,600 2020-02-25
Photo Gallery HIGH 8.8
CVE-2016-10918

The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.

Fix: 1.8.6+
Fix from $1,950 2019-08-22
Popup HIGH 8.8
CVE-2016-10915

The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.

Fix: 1.7.9+
Fix from $1,950 2019-08-20