« Volver al listado

Contest-gallery

Contest-gallery Contest Gallery: vulnerabilidades y CVE

Contest-gallery Contest Gallery tiene 60 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE60
Últimos 12 meses19
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-78088Alta (8.8)0.79%—16 sept 2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to…
CVE-2026-61986Alta (7.1)0.25%—19 ago 2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
CVE-2026-16586Media (6.5)0.55%—15 ago 2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' ->…
CVE-2026-16055Alta (7.5)0.42%—5 ago 2026
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which…
CVE-2026-16056Media (4.3)0.27%—4 ago 2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt…
CVE-2026-16057Media (6.5)0.42%—3 ago 2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any…
CVE-2026-65447Alta (7.1)0.25%—27 jul 2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-57662Alta (8.5)0.36%—26 jun 2026
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
CVE-2026-12165Alta (8.8)0.40%—17 jun 2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter.…
CVE-2026-42660Media (6.5)0.37%—15 jun 2026
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
CVE-2026-42657Media (5.3)0.31%—15 jun 2026
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
CVE-2026-42656Media (6.5)0.22%—15 jun 2026
Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
CVE-2026-40771Crítica (9.3)0.40%—15 jun 2026
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
CVE-2026-8912Alta (7.5)0.51%—19 may 2026
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and…
CVE-2026-4021Alta (8.1)0.73%—24 mar 2026
The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in…
CVE-2026-3180Alta (7.5)0.97%—2 mar 2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to,…
CVE-2026-24965Media (4.3)0.23%—3 feb 2026
Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest…
CVE-2025-12849Media (5.3)0.32%—15 nov 2025
The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both…
CVE-2025-11254Media (4.3)0.34%—11 oct 2025
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for…
CVE-2025-10383Media (6.4)0.25%—4 oct 2025
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is…
CVE-2025-7725Alta (7.2)0.24%—1 ago 2025
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting…
CVE-2025-48291Alta (7.1)0.24%—16 jul 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects…
CVE-2025-6716Media (6.4)0.20%—11 jul 2025
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting…
CVE-2025-3862Media (5.4)0.29%—8 may 2025
Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This…
CVE-2025-1513Media (6.1)0.28%—28 feb 2025
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…
CVE-2025-22693Alta (7.2)0.56%—3 feb 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This issue affects…
CVE-2024-56237Media (4.8)0.33%—2 ene 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects…
CVE-2024-11103Crítica (9.8)0.77%—28 nov 2024
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior…
CVE-2024-10687Crítica (9.8)0.63%—5 nov 2024
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the…
CVE-2024-43283Alta (7.5)1.1%—26 ago 2024
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application7
  2. T1005 Data from Local System6
  3. T1210 Exploitation of Remote Services5
  4. T1059.007 JavaScript4
  5. T1189 Drive-by Compromise3
  6. T1078 Valid Accounts2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.