VendorsContest-Gallerycontest_galleryall versions
Vulnerabilities

Contest-Gallery Contest Gallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2024-30236
WordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerability
Published 2024-03-28 · Modified
9.9EPSS 0.006
CVE-2024-11103
Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover
Published 2024-11-28 · Analyzed
9.8EPSS 0.008
CVE-2024-10687
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection
Published 2024-11-05 · Analyzed
9.8EPSS 0.006
CVE-2019-5974
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published 2019-07-05 · Modified
8.8EPSS 0.010
CVE-2022-36394
WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerability
Published 2022-08-23 · Modified
8.8EPSS 0.010
CVE-2024-30238
WordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerability
Published 2024-03-27 · Modified
8.8EPSS 0.006
CVE-2024-24887
WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2024-02-12 · Modified
8.8EPSS 0.002
CVE-2024-32778
WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability
Published 2024-06-09 · Modified
8.1EPSS 0.006
CVE-2025-22693
WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability
Published 2025-02-03 · Modified
7.6EPSS 0.006
CVE-2024-43283
WordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability
Published 2024-08-26 · Modified
7.5EPSS 0.011
CVE-2022-4156
Contest Gallery < 19.1.5.1 - Unauthenticated SQL Injection
Published 2022-12-26 · Modified
7.5EPSS 0.009
CVE-2022-4158
Contest Gallery < 19.1.5 - Unauthenticated SQL Injection
Published 2022-12-26 · Modified
7.5EPSS 0.009
CVE-2025-1513
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting
Published 2025-02-28 · Analyzed
7.2EPSS 0.003
CVE-2024-30428
WordPress Contest Gallery plugin <= 24.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-29 · Modified
7.1EPSS 0.004
CVE-2023-28784
WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS)
Published 2023-06-22 · Modified
7.1EPSS 0.004
CVE-2024-39631
WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-08-01 · Modified
7.1EPSS 0.003
CVE-2022-4160
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4153
Contest Gallery < 19.1.5.1 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4150
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4151
Contest Gallery < 19.1.5 - Admin+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4166
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4165
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4164
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4163
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4162
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4161
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4159
Contest Gallery < 19.1.5.1 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2022-4152
Contest Gallery < 19.1.5 - Author+ SQL Injection
Published 2022-12-26 · Modified
6.5EPSS 0.009
CVE-2025-3862
Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Published 2025-05-08 · Analyzed
6.4EPSS 0.003
CVE-2023-5307
Photos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP Headers
Published 2023-10-31 · Modified
6.1EPSS 0.005
CVE-2022-45848
WordPress Contest Gallery Plugin <= 13.1.0.9 is vulnerable to Cross Site Scripting (XSS)
Published 2022-12-06 · Modified
6.1EPSS 0.004
CVE-2024-56237
WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability
Published 2025-01-02 · Modified
5.9EPSS 0.003
CVE-2024-1487
Photos and Files Contest Gallery < 21.3.1 - Author+ Stored Cross Site Scripting
Published 2024-03-11 · Analyzed
5.4EPSS 0.004
CVE-2022-4157
Contest Gallery < 19.1.5 - Admin+ SQL Injection
Published 2022-12-26 · Modified
4.9EPSS 0.009
CVE-2022-4154
Contest Gallery Pro < 19.1.5 - Admin+ SQL Injection
Published 2022-12-26 · Modified
4.9EPSS 0.009
CVE-2022-4155
Contest Gallery < 19.1.5 - Admin+ SQL Injection
Published 2022-12-26 · Modified
4.9EPSS 0.008
CVE-2022-27853
WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published 2022-04-18 · Modified
4.8EPSS 0.005