Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown
CVE-2022-4150
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
0
Attacker Value
Unknown
CVE-2022-45848
Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
0
Attacker Value
Unknown
CVE-2022-36394
Disclosure Date: August 09, 2022 (last updated October 08, 2023)
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
0
Attacker Value
Unknown
CVE-2022-27853
Disclosure Date: December 20, 2021 (last updated October 07, 2023)
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
0
Attacker Value
Unknown
CVE-2021-24915
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address
0
Attacker Value
Unknown
CVE-2019-5974
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0