Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's… | |
| Modificada | Alta (7.5) | 0.91% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the… | |
| Modificada | Media (4.9) | 0.91% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress… | |
| Modificada | Alta (7.5) | 0.95% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from the… | |
| Modificada | Media (4.9) | 0.87% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress… | |
| Modificada | Media (4.9) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the… | |
| Modificada | Media (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information… | |
| Modificada | Media (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's… | |
| Modificada | Media (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the… | |
| Modificada | Media (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 26/12/2022 | 17/6/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak… | |
| Modificada | Media (6.1) | 0.43% | — | Contest-gallery Contest Gallery | 6/12/2022 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. | |
| Modificada | Alta (8.8) | 0.96% | — | Contest-gallery Contest Gallery | 23/8/2022 | 17/6/2026 | Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. | |
| Modificada | Media (4.8) | 0.53% | — | Contest-gallery Contest Gallery | 18/4/2022 | 17/6/2026 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9 | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Contest Gallery | 29/11/2021 | 17/6/2026 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the… | |
| Modificada | Alta (8.8) | 1.0% | — | Contest-gallery Contest Gallery | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors. |