Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.79% | — | Contest-gallery Contest GalleryAI | 16/9/2026 | 16/9/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Contest-gallery Contest GalleryAI | 19/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | |
| Aplazada | Media (6.5) | 0.55% | — | Contest-gallery Contest GalleryAI | 15/8/2026 | 20/8/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user… | |
| Aplazada | Alta (7.5) | 0.42% | — | Contest-gallery Contest GalleryAI | 5/8/2026 | 26/8/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin… | |
| Aplazada | Media (4.3) | 0.27% | — | Contest-gallery Contest GalleryAI | 4/8/2026 | 26/8/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history. | |
| Aplazada | Media (6.5) | 0.42% | — | Contest-gallery Contest GalleryAI | 3/8/2026 | 26/8/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contest-gallery Contest GalleryAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Contest-gallery Contest GalleryAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Contest Gallery <= 30.0.0 versions. | |
| Aplazada | Alta (8.8) | 0.40% | — | Contest-gallery Contest GalleryAI | 17/6/2026 | 17/6/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level —… | |
| Aplazada | Media (6.5) | 0.37% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Wasiliy Strecker Contest Gallery PROAI | 1/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1. | |
| Aplazada | Alta (7.5) | 0.51% | — | Contest-gallery Contest GalleryAI | 19/5/2026 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Wasiliy Strecker Contest GalleryAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2. | |
| Aplazada | Media (6.4) | 0.16% | — | Wasiliy Strecker Contest GalleryAI | 25/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.1.2.1. | |
| Aplazada | Alta (8.1) | 0.73% | — | Contest-gallery Contest GalleryAI | 24/3/2026 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID =… | |
| Aplazada | Alta (7.5) | 0.97% | — | Contest-gallery Contest GalleryAI | 2/3/2026 | 17/6/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Media (4.3) | 0.23% | — | Contest-gallery Contest GalleryAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Contest-gallery Contest GalleryAI | 15/11/2025 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce… | |
| Aplazada | Media (4.3) | 0.12% | — | Wasiliy Strecker Contest GalleryAI | 6/11/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Cross Site Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.0.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Contest-gallery Contest GalleryAI | 11/10/2025 | 17/6/2026 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code… | |
| Aplazada | Media (6.4) | 0.25% | — | Contest-gallery Contest GalleryAI | 4/10/2025 | 17/6/2026 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes… | |
| Aplazada | Alta (7.2) | 0.24% | — | Contest-gallery Contest GalleryAI | 1/8/2025 | 17/6/2026 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including, 26.1.0 due to insufficient input… |