Home/Product/sygnoos popup builder
Product

sygnoos popup builder

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-9428
< 4.3.5
The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privile
4.8MEDIUM
CVE-2024-2541
<= 4.3.3
The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6
5.3MEDIUM
CVE-2024-3602
<= 1.1.0
The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers - Promolayer plugin for WordPress is vuln
4.3MEDIUM
CVE-2024-3236
< 1.1.33
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow u
5.4MEDIUM
CVE-2024-2544
< 4.3.2
The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capabi
7.4HIGH
CVE-2023-6696
< 4.3.2
The Popup Builder - Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized
8.1HIGH
CVE-2023-6294
< 4.2.6
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow use
7.2HIGH
CVE-2023-6000
< 4.2.3
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw
6.1MEDIUM
CVE-2023-3226
<= 4.1.15
The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privileg
4.8MEDIUM
CVE-2022-29495
< 4.1.12
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to updat
5.4MEDIUM
CVE-2022-32289
< 4.1.1
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status chan
5.4MEDIUM
CVE-2022-1894
< 4.1.11
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege user
4.8MEDIUM
CVE-2022-0479
< 4.1.1
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using
9.8CRITICAL
CVE-2022-0228
< 4.0.7
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before usin
7.2HIGH
CVE-2021-25082
< 4.0.7
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a requir
8.8HIGH
CVE-2021-24152
< 3.74
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
6.1MEDIUM
CVE-2020-10196
< 3.64.1
An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScrip
6.1MEDIUM
CVE-2020-10195
< 3.64.1
The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope
6.3MEDIUM
CVE-2020-9006
>= 2.2.8 and <= 2.6.7.6
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_
9.8CRITICAL
CVE-2019-14695
< 3.45
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of thi
9.8CRITICAL
threatengine.sh