Supsystic Vulnerabilities
CVE security advisories and vulnerability history for Supsystic.
Overview
Supsystic has 64 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 13 have a known public exploit. The average CVSS base score across scored CVEs is 7.0.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Supsystic products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
Security scorecard
A quick read on Supsystic's vulnerability posture, as a share of its 64 published CVEs.
- Average CVSS
- 7.0
- Critical / high
- 45%
- Actively exploited (KEV)
- 0%
- Public exploit available
- 20%
- Patch available
- 91%
across 64 scored CVEs
29 of 64 scored
0 of 64 CVEs
13 of 64 CVEs
58 of 64 CVEs
Severity and exploitation
How the CVSS severity of Supsystic's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Supsystic's CVEs are currently listed in CISA's KEV catalog.
Public exploits
13
13 of Supsystic's CVEs have a known public exploit available.
Most affected products
The Supsystic products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
Common weakness types
The CWE weakness categories most often found in Supsystic CVEs. Follow any weakness for its full explanation.
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17 CVEs
- CWE-352Cross-Site Request Forgery (CSRF)14 CVEs
- CWE-862Missing Authorization7 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5 CVEs
- CWE-82Improper Neutralization of Script in Attributes of IMG Tags in a Web Page2 CVEs
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2 CVEs
- CWE-94Improper Control of Generation of Code ('Code Injection')1 CVE
- CWE-98Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1 CVE
CNAs that assign these CVEs
The CVE Numbering Authorities that publish Supsystic CVE records.
Disclosure activity by year
How many Supsystic CVEs were published each year.
Latest Supsystic CVEs
The most recently disclosed vulnerabilities affecting Supsystic.
- Medium · CVSS 5.9EPSS 0.2%2026-07-23
- Medium · CVSS 6.9EPSS 0.7%2026-05-16
- High · CVSS 8.7EPSS 0.5%2026-05-16
- High · CVSS 8.8EPSS 0.3%2026-05-16
- High · CVSS 8.8EPSS 0.3%2026-05-16
- High · CVSS 8.8EPSS 0.3%2026-05-16
- Critical · CVSS 9.8EPSS 41.5%2026-03-30
- Medium · CVSS 6.5EPSS 0.6%2025-11-13
- High · CVSS 7.1EPSS 0.2%2025-10-22
- Medium · CVSS 6.1EPSS 0.3%2025-04-16
- Medium · CVSS 6.6EPSS 0.5%2025-04-04
- WordPress Data Tables Generator by Supsystic plugin <= 1.10.36 - Broken Access Control vulnerabilityMedium · CVSS 5.4EPSS 0.3%2025-01-02
Track new Supsystic CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor Supsystic CVEsOther vendors
Browse vulnerabilities for other tracked vendors.
Frequently asked questions
Common questions about Supsystic vulnerabilities.
- How many CVEs does Supsystic have?
- Supsystic has 64 published CVE records since 2019, including 12 in the last two years.
- How many Supsystic CVEs are in CISA KEV?
- None of Supsystic's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which Supsystic products have the most CVEs?
- The Supsystic products with the most published CVEs are popup, Contact Form by Supsystic, Easy Google Maps, Popup by Supsystic, social share buttons.
- What are the most common weakness types in Supsystic CVEs?
- Supsystic's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-352 (Cross-Site Request Forgery (CSRF)), CWE-862 (Missing Authorization), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
- Are there public exploits for Supsystic vulnerabilities?
- Yes — 13 of Supsystic's CVEs have a known public exploit.
- How many critical Supsystic vulnerabilities are there?
- Supsystic has 6 critical and 23 high-severity CVEs.
- What is the average severity of Supsystic CVEs?
- The average CVSS base score across Supsystic's scored CVEs is 7.0.
References
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
- CNA directory: the CNAs that assign these CVEs
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track Supsystic vulnerabilities
Monitor new Supsystic vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.