Vulnerabilities

Summary — last 7 days

New vulnerabilities2,744▼ 111 vs. last week
Critical / high1,254▼ 280 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
–

62 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.79%—Contest-gallery Contest GalleryAI9/16/20269/16/2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for…
DeferredHigh (7.1)0.25%—Contest-gallery Contest GalleryAI8/19/20268/20/2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
DeferredMedium (6.5)0.55%—Contest-gallery Contest GalleryAI8/15/20268/20/2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user…
DeferredHigh (7.5)0.42%—Contest-gallery Contest GalleryAI8/5/20268/26/2026
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin…
DeferredMedium (4.3)0.27%—Contest-gallery Contest GalleryAI8/4/20268/26/2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.
DeferredMedium (6.5)0.42%—Contest-gallery Contest GalleryAI8/3/20268/26/2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
DeferredHigh (7.1)0.25%—Contest-gallery Contest GalleryAI7/27/20267/28/2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
DeferredHigh (8.5)0.36%—Contest-gallery Contest GalleryAI6/26/20266/26/2026
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
DeferredHigh (8.8)0.40%—Contest-gallery Contest GalleryAI6/17/20266/17/2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level —…
DeferredMedium (6.5)0.37%—Contest-gallery Contest GalleryAI6/15/20266/17/2026
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
DeferredMedium (5.3)0.31%—Contest-gallery Contest GalleryAI6/15/20266/17/2026
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
DeferredMedium (6.5)0.22%—Contest-gallery Contest GalleryAI6/15/20266/17/2026
Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
DeferredCritical (9.3)0.40%—Contest-gallery Contest GalleryAI6/15/20266/17/2026
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
DeferredHigh (7.5)0.51%—Contest-gallery Contest GalleryAI5/19/20266/17/2026
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated…
DeferredHigh (8.1)0.73%—Contest-gallery Contest GalleryAI3/24/20266/17/2026
The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID =…
DeferredHigh (7.5)0.97%💥 ExploitContest-gallery Contest GalleryAI3/2/20266/17/2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of…
DeferredMedium (4.3)0.23%—Contest-gallery Contest GalleryAI2/3/20266/17/2026
Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1.
DeferredMedium (5.3)0.32%—Contest-gallery Contest GalleryAI11/15/202510/7/2026
The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce…
DeferredMedium (4.3)0.34%—Contest-gallery Contest GalleryAI10/11/202510/8/2026
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code…
DeferredMedium (6.4)0.25%—Contest-gallery Contest GalleryAI10/4/202510/8/2026
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes…
DeferredHigh (7.2)0.24%—Contest-gallery Contest GalleryAI8/1/20256/17/2026
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including, 26.1.0 due to insufficient input…
DeferredHigh (7.1)0.26%—Contest-gallery Contest GalleryAI7/16/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through <= 26.0.6.
DeferredMedium (6.4)0.20%—Contest-gallery Contest GalleryAI7/11/20256/17/2026
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'upload[1][title]' parameter in all versions up to, and including, 26.0.8 due to…
AnalyzedMedium (5.4)0.29%—Contest-gallery Contest Gallery5/8/20256/17/2026
Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AnalyzedMedium (6.1)0.28%—Contest-gallery Contest Gallery2/28/20256/17/2026
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting on photo gallery entries in all versions up to, and…