Home/Product/contest gallery contest gallery
Product

contest gallery contest gallery

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3862
< 26.0.7
Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to
6.4MEDIUM
CVE-2025-1513
< 26.0.1
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal or Stripe, Socia
7.2HIGH
CVE-2025-22693
< 25.1.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGa
7.6HIGH
CVE-2024-56237
< 24.0.4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGa
5.9MEDIUM
CVE-2024-11103
< 24.0.8
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc
9.8CRITICAL
CVE-2024-10687
< 24.0.4
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal, Social Share Bu
9.8CRITICAL
CVE-2024-43283
< 23.1.3
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery con
5.3MEDIUM
CVE-2024-39631
< 23.1.3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGa
7.1HIGH
CVE-2024-32778
< 21.3.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery
7.7HIGH
CVE-2024-30428
< 24.0.4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGa
7.1HIGH
CVE-2024-30236
< 21.3.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGa
8.5HIGH
CVE-2024-30238
< 21.3.2.1
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGa
8.5HIGH
CVE-2024-1487
< 21.3.1
The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allo
5.4MEDIUM
CVE-2024-24887
< 21.2.9
Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery - Contact Form, Upload Form, S
5.4MEDIUM
CVE-2023-5307
< 21.2.8.1
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could al
6.1MEDIUM
CVE-2023-28784
<= 21.1.2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.
7.1HIGH
CVE-2022-4166
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCo
6.5MEDIUM
CVE-2022-4165
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_or
6.5MEDIUM
CVE-2022-4164
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_mu
6.5MEDIUM
CVE-2022-4163
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_de
6.5MEDIUM
CVE-2022-4162
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_ro
6.5MEDIUM
CVE-2022-4161
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_co
6.5MEDIUM
CVE-2022-4160
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_co
6.5MEDIUM
CVE-2022-4159
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id
6.5MEDIUM
CVE-2022-4158
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fi
7.5HIGH
CVE-2022-4157
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_op
4.9MEDIUM
CVE-2022-4156
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_
7.5HIGH
CVE-2022-4155
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_us
4.9MEDIUM
CVE-2022-4154
< 19.1.5.1
The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an
4.9MEDIUM
CVE-2022-4153
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the uploa
6.5MEDIUM
CVE-2022-4152
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id
6.5MEDIUM
CVE-2022-4151
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the optio
6.5MEDIUM
CVE-2022-4150
< 19.1.5.1
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the optio
6.5MEDIUM
CVE-2022-45848
<= 13.1.0.9
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
6.1MEDIUM
CVE-2022-36394
<= 17.0.4
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
7.6HIGH
CVE-2022-27853
<= 13.1.0.9
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
4.8MEDIUM
CVE-2021-24915
< 13.1.0.6
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search
9.8CRITICAL
CVE-2019-5974
< 10.4.5
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the
8.8HIGH
threatengine.sh