Vulnerabilities
Summary — last 7 days
New vulnerabilities2,744▼ 111 vs. last week
Critical / high1,254▼ 280 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
62 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.8) | 0.79% | — | Contest-gallery Contest GalleryAI | 9/16/2026 | 9/16/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for… | |
| Deferred | High (7.1) | 0.25% | — | Contest-gallery Contest GalleryAI | 8/19/2026 | 8/20/2026 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | |
| Deferred | Medium (6.5) | 0.55% | — | Contest-gallery Contest GalleryAI | 8/15/2026 | 8/20/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user… | |
| Deferred | High (7.5) | 0.42% | — | Contest-gallery Contest GalleryAI | 8/5/2026 | 8/26/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin… | |
| Deferred | Medium (4.3) | 0.27% | — | Contest-gallery Contest GalleryAI | 8/4/2026 | 8/26/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history. | |
| Deferred | Medium (6.5) | 0.42% | — | Contest-gallery Contest GalleryAI | 8/3/2026 | 8/26/2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. | |
| Deferred | High (7.1) | 0.25% | — | Contest-gallery Contest GalleryAI | 7/27/2026 | 7/28/2026 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | |
| Deferred | High (8.5) | 0.36% | — | Contest-gallery Contest GalleryAI | 6/26/2026 | 6/26/2026 | Contributor SQL Injection in Contest Gallery <= 30.0.0 versions. | |
| Deferred | High (8.8) | 0.40% | — | Contest-gallery Contest GalleryAI | 6/17/2026 | 6/17/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level —… | |
| Deferred | Medium (6.5) | 0.37% | — | Contest-gallery Contest GalleryAI | 6/15/2026 | 6/17/2026 | Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. | |
| Deferred | Medium (5.3) | 0.31% | — | Contest-gallery Contest GalleryAI | 6/15/2026 | 6/17/2026 | Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. | |
| Deferred | Medium (6.5) | 0.22% | — | Contest-gallery Contest GalleryAI | 6/15/2026 | 6/17/2026 | Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. | |
| Deferred | Critical (9.3) | 0.40% | — | Contest-gallery Contest GalleryAI | 6/15/2026 | 6/17/2026 | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. | |
| Deferred | High (7.5) | 0.51% | — | Contest-gallery Contest GalleryAI | 5/19/2026 | 6/17/2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated… | |
| Deferred | High (8.1) | 0.73% | — | Contest-gallery Contest GalleryAI | 3/24/2026 | 6/17/2026 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID =… | |
| Deferred | High (7.5) | 0.97% | 💥 Exploit | Contest-gallery Contest GalleryAI | 3/2/2026 | 6/17/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of… | |
| Deferred | Medium (4.3) | 0.23% | — | Contest-gallery Contest GalleryAI | 2/3/2026 | 6/17/2026 | Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1. | |
| Deferred | Medium (5.3) | 0.32% | — | Contest-gallery Contest GalleryAI | 11/15/2025 | 10/7/2026 | The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce… | |
| Deferred | Medium (4.3) | 0.34% | — | Contest-gallery Contest GalleryAI | 10/11/2025 | 10/8/2026 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code… | |
| Deferred | Medium (6.4) | 0.25% | — | Contest-gallery Contest GalleryAI | 10/4/2025 | 10/8/2026 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes… | |
| Deferred | High (7.2) | 0.24% | — | Contest-gallery Contest GalleryAI | 8/1/2025 | 6/17/2026 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including, 26.1.0 due to insufficient input… | |
| Deferred | High (7.1) | 0.26% | — | Contest-gallery Contest GalleryAI | 7/16/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through <= 26.0.6. | |
| Deferred | Medium (6.4) | 0.20% | — | Contest-gallery Contest GalleryAI | 7/11/2025 | 6/17/2026 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'upload[1][title]' parameter in all versions up to, and including, 26.0.8 due to… | |
| Analyzed | Medium (5.4) | 0.29% | — | Contest-gallery Contest Gallery | 5/8/2025 | 6/17/2026 | Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analyzed | Medium (6.1) | 0.28% | — | Contest-gallery Contest Gallery | 2/28/2025 | 6/17/2026 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting on photo gallery entries in all versions up to, and… |