WordPress security by component
Contest Gallery
Plugin description
Contest Gallery creates photo contests and galleries where visitors can submit, display, and vote on images.
Contest Gallery (contest-gallery) is a WordPress plugin with 60 published CVE records in this archive. The latest tracked vulnerability was published Aug 19, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
contest-galleryLatest vulnerability
CVE-2026-61986: Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 30.0.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Aug 19, 2026 |
CVE-2026-61986
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 30.0.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
30.0.6 |
CVE7.1
NVDPending
|
| Aug 15, 2026 |
CVE-2026-16586
Contest Gallery multiple-file metadata permits Author second-order SQL injection
Contest Gallery through 30.0.7 stores attacker input through cg_multiple_files_for_post and later uses the stored cgRealId value in SQL without adequate preparation. An Author can plant a second-order payload that appends SQL when the later gallery operation processes it, enabling sensitive database extraction. The public CNA does not disclose the AJAX action, storage format, triggering operation, final query, or payload.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 05, 2026 |
CVE-2026-16055
Contest Gallery login bypasses two-factor and brute-force controls
Contest Gallery before 30.0.7 authenticates its front-end login by checking the password and issuing a WordPress authentication cookie directly instead of using the standard WordPress login flow. Installed brute-force protection and two-factor authentication therefore do not run. An unauthenticated attacker can make unlimited password guesses against any account and, after finding a valid password, receive a session without completing the second factor, including for an administrator. This unscored record received deeper review because it is an authentication-control bypass; the CNA does not disclose the front-end route or parameters.
|
30.0.7 |
CVE7.5
NVDPending
|
| Aug 04, 2026 |
CVE-2026-16056
Contest Gallery exposes the complete OpenAI prompt history to Subscribers
Contest Gallery before 30.0.7 omits both capability and nonce checks from a handler that returns the site's stored OpenAI prompt history. Any authenticated user, including a Subscriber, can invoke it and read every retained prompt, which may contain private instructions or submitted content. The public advisory does not disclose the handler route, action, callback or response schema.
|
30.0.7 |
CVE4.3
NVDPending
|
| Aug 03, 2026 |
CVE-2026-16057
Contest Gallery lets Authors permanently delete arbitrary content
Contest Gallery before 30.0.7 gates a post-deletion handler only with a coarse role-membership test and omits per-object capability and nonce checks. An Author-or-higher user can supply arbitrary object identifiers and permanently delete posts, pages and other content they do not own. The CNA record does not disclose the handler, identifier parameter or deletion function.
|
30.0.7 |
CVE6.5
NVDPending
|
| Jul 27, 2026 |
CVE-2026-65447
Contest Gallery public input permits cross-site scripting
Contest Gallery through 30.0.6 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, action, parameter or rendering function.
|
30.0.7 |
CVE7.1
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57662
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 30.0.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
30.0.1 |
CVE8.5
NVDPending
|
| Jun 17, 2026 |
CVE-2026-12165
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: Privilege escalation or authentication bypass
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated author account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 30.0.2.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42660
Contest Gallery: Sensitive information exposure
Contest Gallery is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 28.1.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
29.0.0 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42657
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 28.1.7. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
29.0.0 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42656
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 28.1.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
29.0.0 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40771
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 28.1.6. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
28.1.7 |
CVE9.3
NVDPending
|
| May 19, 2026 |
CVE-2026-8912
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: SQL injection
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 28.1.6.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Mar 25, 2026 |
CVE-2026-25035
Contest Gallery: Privilege escalation or authentication bypass
Contest Gallery is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 28.1.2.2. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
28.1.3 |
CVE9.8
NVDPending
|
| Mar 25, 2026 |
CVE-2026-24964
Contest Gallery: Server-side request forgery
Contest Gallery is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 28.1.2.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
28.1.2.2 |
CVE6.4
NVDPending
|
| Mar 24, 2026 |
CVE-2026-4021
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: Privilege escalation or authentication bypass
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 28.1.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Mar 02, 2026 |
CVE-2026-3180
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: SQL injection
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24965
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 15, 2025 |
CVE-2025-12849
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62950
Contest Gallery: Cross-site request forgery
Contest Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 04, 2025 |
CVE-2025-10383
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe: Cross-site scripting
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 16, 2025 |
CVE-2025-48291
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVDPending
|
| May 08, 2025 |
CVE-2025-3862
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 28, 2025 |
CVE-2025-1513
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Feb 03, 2025 |
CVE-2025-22693
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jan 02, 2025 |
CVE-2024-56237
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 28, 2024 |
CVE-2024-11103
Contest Gallery: Privilege escalation or authentication bypass
Contest Gallery is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Nov 05, 2024 |
CVE-2024-10687
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons: SQL injection
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 26, 2024 |
CVE-2024-43283
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Aug 01, 2024 |
CVE-2024-39631
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jun 09, 2024 |
CVE-2024-32778
Contest Gallery: Filesystem traversal
Contest Gallery is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.7
NVD8.1
|
| Mar 29, 2024 |
CVE-2024-30428
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 28, 2024 |
CVE-2024-30236
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.5
NVD9.9
|
| Mar 27, 2024 |
CVE-2024-30238
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Mar 11, 2024 |
CVE-2024-1487
Photos and Files Contest Gallery: Cross-site scripting
Photos and Files Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Feb 12, 2024 |
CVE-2024-24887
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: Cross-site request forgery
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Oct 31, 2023 |
CVE-2023-5307
Photos and Files Contest Gallery: Cross-site scripting
Photos and Files Contest Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 22, 2023 |
CVE-2023-28784
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Dec 26, 2022 |
CVE-2022-4166
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4165
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4164
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4163
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4162
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4161
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4160
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4159
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4158
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 26, 2022 |
CVE-2022-4157
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exploitation requires an authenticated administrator account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4156
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Dec 26, 2022 |
CVE-2022-4155
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exploitation requires an authenticated administrator account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4154
Contest Gallery Pro: A security weakness
Contest Gallery Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.9
NVD4.9
|
| Dec 26, 2022 |
CVE-2022-4153
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4152
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4151
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 26, 2022 |
CVE-2022-4150
Contest Gallery: A security weakness
Contest Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Dec 06, 2022 |
CVE-2022-45848
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 23, 2022 |
CVE-2022-36394
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.6
NVD8.8
|
| Apr 18, 2022 |
CVE-2022-27853
Contest Gallery: Cross-site scripting
Contest Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Nov 29, 2021 |
CVE-2021-24915
Contest Gallery: SQL injection
Contest Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Jul 05, 2019 |
CVE-2019-5974
Contest Gallery: Cross-site request forgery
Contest Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD8.8
|