Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-3862 Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6… Contest Gallery 26.0.7+ Fix from $1,6002025-05-08 MEDIUM 6.1 CVE-2025-1513 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plu… Contest Gallery 26.0.1+ Fix from $1,6002025-02-28 HIGH 7.2 CVE-2025-22693 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con… Contest Gallery 25.1.2+ Fix from $1,9502025-02-03 CRITICAL 9.8 CVE-2024-11103 The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. Thi… Contest Gallery 24.0.8+ Fix from $2,3002024-11-28 CRITICAL 9.8 CVE-2024-10687 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for Wo… Contest Gallery 24.0.4+ Fix from $2,3002024-11-05 HIGH 7.5 CVE-2024-43283 Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This i… Contest Gallery 23.1.3+ Fix from $1,9502024-08-26 MEDIUM 6.1 CVE-2024-39631 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Con… Contest Gallery 23.1.3+ Fix from $1,6002024-08-01 HIGH 8.1 CVE-2024-32778 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest G… Contest Gallery 21.3.5+ Fix from $1,9502024-06-09 MEDIUM 6.1 CVE-2024-30428 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Con… Contest Gallery 24.0.4+ Fix from $1,6002024-03-29 CRITICAL 9.9 CVE-2024-30236 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con… Contest Gallery 21.3.5+ Fix from $2,3002024-03-28 HIGH 8.8 CVE-2024-30238 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con… Contest Gallery 21.3.2.1+ Fix from $1,9502024-03-27 MEDIUM 5.4 CVE-2024-1487 The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role… Contest Gallery 21.3.1+ Fix from $1,6002024-03-11 HIGH 8.8 CVE-2024-24887 Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Vot… Contest Gallery 21.2.9+ Fix from $1,9502024-02-12 MEDIUM 6.1 CVE-2023-5307 The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated… Contest Gallery 21.2.8.1+ Fix from $1,6002023-10-31 MEDIUM 6.1 CVE-2023-28784 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions. Contest Gallery after 21.1.2 Fix from $1,6002023-06-22 HIGH 7.5 CVE-2022-4158 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter… Contest Gallery 19.1.5.1+ Fix from $1,9502022-12-26 MEDIUM 6.5 CVE-2022-4159 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter bef… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4160 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST paramete… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4161 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST param… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4162 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter be… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4163 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_act… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4164 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_po… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4165 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter … Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4166 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 HIGH 7.5 CVE-2022-4156 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter b… Contest Gallery 19.1.5.1+ Fix from $1,9502022-12-26 MEDIUM 6.5 CVE-2022-4150 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4151 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter … Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4152 The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter bef… Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.5 CVE-2022-4153 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter … Contest Gallery 19.1.5.1+ Fix from $1,6002022-12-26 MEDIUM 6.1 CVE-2022-45848 Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. Contest Gallery after 13.1.0.9 Fix from $1,6002022-12-06