Skip to main content

Vendor archive

contest-gallery CVEs

Beta · best-effort

37 CVEs tagged to vendor contest-gallery2 Critical, 12 High, 23 Medium, 0 Low, 0 Unrated.

CVE-2022-4157

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4156

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4155

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4154

Published Dec 26, 2022

The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4153

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4152

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4151

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4150

Published Dec 26, 2022

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5974

Published Jul 5, 2019

Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-37 of 37 CVEsPage 2 of 2