Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown

CVE-2022-45848

Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
Attacker Value
Unknown

CVE-2022-36394

Disclosure Date: August 09, 2022 (last updated October 08, 2023)
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
Attacker Value
Unknown

CVE-2022-27853

Disclosure Date: December 20, 2021 (last updated October 07, 2023)
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
Attacker Value
Unknown

CVE-2021-24915

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address
Attacker Value
Unknown

CVE-2019-5974

Disclosure Date: July 05, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0