Skip to main content

Vendor archive

contest-gallery CVEs

Beta · best-effort

37 CVEs tagged to vendor contest-gallery2 Critical, 12 High, 23 Medium, 0 Low, 0 Unrated.

CVE-2025-3862

Published May 8, 2025

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input san…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1513

Published Feb 28, 2025

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerabl…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22693

Published Feb 3, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56237

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11103

Published Nov 28, 2024

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not pro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10687

Published Nov 5, 2024

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43283

Published Aug 26, 2024

Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery:…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39631

Published Aug 1, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.T…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32778

Published Jun 9, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This is…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30428

Published Mar 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30236

Published Mar 28, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.T…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30238

Published Mar 27, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.T…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1487

Published Mar 11, 2024

The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform C…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24887

Published Feb 12, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5307

Published Oct 31, 2023

The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site S…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28784

Published Jun 22, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4166

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4165

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4164

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before conca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4163

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4162

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4161

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4160

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4159

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4158

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2