Vulnerabilities
Summary — last 7 days
New vulnerabilities2,737▼ 82 vs. last week
Critical / high1,248▼ 291 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)249▲ 212 vs. last week
62 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.9) | 0.87% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress… | |
| Modified | Medium (4.9) | 0.88% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the… | |
| Modified | Medium (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information… | |
| Modified | Medium (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's… | |
| Modified | Medium (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the… | |
| Modified | Medium (6.5) | 0.88% | — | Contest-gallery Contest Gallery | 12/26/2022 | 6/17/2026 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak… | |
| Modified | Medium (6.1) | 0.43% | — | Contest-gallery Contest Gallery | 12/6/2022 | 6/17/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. | |
| Modified | High (8.8) | 0.96% | — | Contest-gallery Contest Gallery | 8/23/2022 | 6/17/2026 | Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. | |
| Modified | Medium (4.8) | 0.53% | — | Contest-gallery Contest Gallery | 4/18/2022 | 6/17/2026 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9 | |
| Modified | High (8.8) | 1.0% | — | Contest-gallery Contest Gallery | 7/5/2019 | 6/17/2026 | Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modified | Low (2.6) | 2.1% | — | Marcel Brinkkemper Lazyest-gallery | 4/11/2014 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information. | |
| Modified | Medium (6.8) | 0.93% | 💥 Exploit | Sebastian-thiele St-gallery | 5/28/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php. |