← Vulnerability feed

Vulnerability record · CVE-2023-46197 · published 17 May 2024

CVE-2023-46197: Supsystic popup path traversal vulnerability

Supsystic · Popup

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

6.5 CVSS 3.1 Medium EPSS 1.3% · top 31.4% CWE-22 · Path traversal
6.5CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46197 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39997Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This …EPSS 0.67%9.8CVE-2023-51353Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Securi…EPSS 0.57%9.8CVE-2023-3186Supsystic popup vulnerabilityThe Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary prope…EPSS 1.5%9.1CVE-2024-52434Supsystic popup code injection vulnerabilityDeserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup …EPSS 1.1%8.8CVE-2016-10915Supsystic popup cross-site request forgery vulnerabilityThe popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.EPSS 0.68%6.1CVE-2021-24275Supsystic popup cross-site scripting vulnerabilityThe Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, le…EPSS 18%5.3CVE-2022-0424Supsystic popup missing authentication for critical function vulnerabilityThe Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated …EPSS 2.9%4.3CVE-2024-31421Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.1…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2023-46197), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.