WordPress security by component
Contest Gallery
Plugin description
Contest Gallery is a WordPress component with 55 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
contest-galleryLatest vulnerability
CVE-2026-65447: Contest Gallery public input permits cross-site scripting
Contest Gallery through 30.0.6 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, action, parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-65447
Contest Gallery public input permits cross-site scripting
Contest Gallery through 30.0.6 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, action, parameter or rendering function.
|
30.0.7 |
CVE7.1
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57662
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 30.0.0.
|
30.0.1 |
CVE8.5
NVDPending
|
| Jun 17, 2026 |
CVE-2026-12165
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: Privilege escalation or authentication bypass
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by privilege escalation or authentication bypass. Exploitation requires at least author-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 30.0.2.
|
> 30.0.2 |
CVE8.8
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42660
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 28.1.7.
|
29.0.0 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42657
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 28.1.7.
|
29.0.0 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42656
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 28.1.6.
|
29.0.0 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40771
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 28.1.6.
|
28.1.7 |
CVE9.3
NVDPending
|
| May 19, 2026 |
CVE-2026-8912
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: SQL injection
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 28.1.6.
|
> 28.1.6 |
CVE7.5
NVDPending
|
| Mar 25, 2026 |
CVE-2026-25035
Contest Gallery: Privilege escalation or authentication bypass
Contest Gallery is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 28.1.2.2.
|
28.1.3 |
CVE9.8
NVDPending
|
| Mar 25, 2026 |
CVE-2026-24964
Contest Gallery: Server-side request forgery
Contest Gallery is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 28.1.2.1.
|
28.1.2.2 |
CVE6.4
NVDPending
|
| Mar 24, 2026 |
CVE-2026-4021
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: Privilege escalation or authentication bypass
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 28.1.5.
|
> 28.1.5 |
CVE8.1
NVDPending
|
| Mar 02, 2026 |
CVE-2026-3180
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: SQL injection
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24965
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 15, 2025 |
CVE-2025-12849
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62950
Contest Gallery: Cross-site request forgery
Contest Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 04, 2025 |
CVE-2025-10383
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe: Cross-site scripting
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 16, 2025 |
CVE-2025-48291
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| May 08, 2025 |
CVE-2025-3862
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 28, 2025 |
CVE-2025-1513
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Feb 03, 2025 |
CVE-2025-22693
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jan 02, 2025 |
CVE-2024-56237
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 28, 2024 |
CVE-2024-11103
Contest Gallery: Privilege escalation or authentication bypass
Contest Gallery is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Nov 05, 2024 |
CVE-2024-10687
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons: SQL injection
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 26, 2024 |
CVE-2024-43283
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Aug 01, 2024 |
CVE-2024-39631
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jun 09, 2024 |
CVE-2024-32778
Contest Gallery: Filesystem traversal
Contest Gallery is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.7
NVD8.1
|
| Mar 29, 2024 |
CVE-2024-30428
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 28, 2024 |
CVE-2024-30236
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD9.9
|
| Mar 27, 2024 |
CVE-2024-30238
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Mar 11, 2024 |
CVE-2024-1487
Photos and Files Contest Gallery: Cross-site scripting
Photos and Files Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Feb 12, 2024 |
CVE-2024-24887
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: Cross-site request forgery
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Oct 31, 2023 |
CVE-2023-5307
Photos and Files Contest Gallery: Cross-site scripting
Photos and Files Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 22, 2023 |
CVE-2023-28784
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Dec 26, 2022 |
CVE-2022-4166
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4165
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4164
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4163
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4162
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4161
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4160
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4159
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4158
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 26, 2022 |
CVE-2022-4157
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4156
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 26, 2022 |
CVE-2022-4155
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4154
Contest Gallery Pro: A security weakness
Contest Gallery Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4153
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4152
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4151
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4150
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 06, 2022 |
CVE-2022-45848
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 23, 2022 |
CVE-2022-36394
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD8.8
|
| Apr 18, 2022 |
CVE-2022-27853
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Nov 29, 2021 |
CVE-2021-24915
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jul 05, 2019 |
CVE-2019-5974
Contest Gallery: Cross-site request forgery
Contest Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|