CVEs we hold for Contest
Records whose assigning authority named Contest as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-8912Contest Gallery <= 28.1.6 - Unauthenticated SQL Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-78088Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-4021Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-3180Contest Gallery <= 28.1.4 - Unauthenticated SQL Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-16586Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-16057Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_libraryUnknown Contest Gallery
CVE-2026-16056Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_promptsUnknown Contest Gallery
CVE-2026-16055Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_loginUnknown Contest Gallery
CVE-2026-12165Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-7725Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-6716Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scriptingcontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-3862Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-1513Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-12849Contest Gallery <= 28.0.2 - Missing Authorizationcontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-11254Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-10383Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2024-24887WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF)Contest Gallery – Contact Form, Upload Form, Social Share…
CVE-2024-11103Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeovercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2024-10687Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2023-28784WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS)Contest Gallery
CVE-2022-45848WordPress Contest Gallery Plugin <= 13.1.0.9 is vulnerable to Cross Site Scripting (XSS)Contest Gallery
CVE-2022-36394WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerabilityContest Gallery (WordPress plugin)
CVE-2022-27853WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityContest Gallery (WordPress plugin)
CVE-2021-24915Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address DisclosureUnknown Contest Gallery – Photo Contest Plugin for WordPress
42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.