Vulnerabilities

Summary — last 7 days

New vulnerabilities2,737▼ 82 vs. last week
Critical / high1,248▼ 291 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)249▲ 212 vs. last week
–

62 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.9)0.87%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress…
ModifiedMedium (4.9)0.88%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the…
ModifiedMedium (6.5)0.88%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information…
ModifiedMedium (6.5)0.88%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's…
ModifiedMedium (6.5)0.88%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the…
ModifiedMedium (6.5)0.88%—Contest-gallery Contest Gallery12/26/20226/17/2026
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak…
ModifiedMedium (6.1)0.43%—Contest-gallery Contest Gallery12/6/20226/17/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
ModifiedHigh (8.8)0.96%—Contest-gallery Contest Gallery8/23/20226/17/2026
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
ModifiedMedium (4.8)0.53%—Contest-gallery Contest Gallery4/18/20226/17/2026
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
ModifiedHigh (8.8)1.0%—Contest-gallery Contest Gallery7/5/20196/17/2026
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModifiedLow (2.6)2.1%—Marcel Brinkkemper Lazyest-gallery4/11/20146/17/2026
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
ModifiedMedium (6.8)0.93%💥 ExploitSebastian-thiele St-gallery5/28/20096/16/2026
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php.