contest-gallery
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting contest-gallery.
- CVE-2026-12165Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter8.8
- CVE-2026-8912Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection7.5
- CVE-2026-4021Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion8.1
- CVE-2026-3180Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection7.5
- CVE-2025-12849Contest Gallery <= 28.0.2 - Missing Authorization5.3
- CVE-2025-11254Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection4.3
- CVE-2025-10383Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting6.4
- CVE-2025-7725Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2025-6716Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting6.4
- CVE-2025-3862Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter6.4
- CVE-2025-1513Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2025-22693WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability7.6
- CVE-2024-56237WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability5.9
- CVE-2024-11103Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover9.8
- CVE-2024-10687Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection9.8