Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Contest Gallery MEDIUM 5.4
CVE-2025-3862

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6…

Fix: 26.0.7+
Fix from $1,600 2025-05-08
Contest Gallery MEDIUM 6.1
CVE-2025-1513

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plu…

Fix: 26.0.1+
Fix from $1,600 2025-02-28
Contest Gallery HIGH 7.2
CVE-2025-22693

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con…

Fix: 25.1.2+
Fix from $1,950 2025-02-03
Contest Gallery CRITICAL 9.8
CVE-2024-11103

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. Thi…

Fix: 24.0.8+
Fix from $2,300 2024-11-28
Contest Gallery CRITICAL 9.8
CVE-2024-10687

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for Wo…

Fix: 24.0.4+
Fix from $2,300 2024-11-05
Contest Gallery HIGH 7.5
CVE-2024-43283

Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This i…

Fix: 23.1.3+
Fix from $1,950 2024-08-26
Contest Gallery MEDIUM 6.1
CVE-2024-39631

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Con…

Fix: 23.1.3+
Fix from $1,600 2024-08-01
Contest Gallery HIGH 8.1
CVE-2024-32778

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest G…

Fix: 21.3.5+
Fix from $1,950 2024-06-09
Contest Gallery MEDIUM 6.1
CVE-2024-30428

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Con…

Fix: 24.0.4+
Fix from $1,600 2024-03-29
Contest Gallery CRITICAL 9.9
CVE-2024-30236

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con…

Fix: 21.3.5+
Fix from $2,300 2024-03-28
Contest Gallery HIGH 8.8
CVE-2024-30238

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Con…

Fix: 21.3.2.1+
Fix from $1,950 2024-03-27
Contest Gallery MEDIUM 5.4
CVE-2024-1487

The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role…

Fix: 21.3.1+
Fix from $1,600 2024-03-11
Contest Gallery HIGH 8.8
CVE-2024-24887

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Vot…

Fix: 21.2.9+
Fix from $1,950 2024-02-12
Contest Gallery MEDIUM 6.1
CVE-2023-5307

The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated…

Fix: 21.2.8.1+
Fix from $1,600 2023-10-31
Contest Gallery MEDIUM 6.1
CVE-2023-28784

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.

Fix: after 21.1.2
Fix from $1,600 2023-06-22
Contest Gallery HIGH 7.5
CVE-2022-4158

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter…

Fix: 19.1.5.1+
Fix from $1,950 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4159

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter bef…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4160

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST paramete…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4161

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST param…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4162

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter be…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4163

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_act…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4164

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_po…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4165

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter …

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4166

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery HIGH 7.5
CVE-2022-4156

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter b…

Fix: 19.1.5.1+
Fix from $1,950 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4150

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4151

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter …

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4152

The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter bef…

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.5
CVE-2022-4153

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter …

Fix: 19.1.5.1+
Fix from $1,600 2022-12-26
Contest Gallery MEDIUM 6.1
CVE-2022-45848

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.

Fix: after 13.1.0.9
Fix from $1,600 2022-12-06