vciy

CVEs we hold for Contest

Records whose assigning authority named Contest as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8912Contest Gallery <= 28.1.6 - Unauthenticated SQL Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-78088Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-4021Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-3180Contest Gallery <= 28.1.4 - Unauthenticated SQL Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-16586Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2026-16057Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_libraryUnknown Contest Gallery
CVE-2026-16056Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_promptsUnknown Contest Gallery
CVE-2026-16055Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_loginUnknown Contest Gallery
CVE-2026-12165Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-7725Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-6716Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scriptingcontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-3862Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parametercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-1513Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-12849Contest Gallery <= 28.0.2 - Missing Authorizationcontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-11254Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injectioncontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2025-10383Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2024-24887WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF)Contest Gallery – Contact Form, Upload Form, Social Share…
CVE-2024-11103Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeovercontest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2024-10687Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social…contest-gallery Contest Gallery – Upload & Vote Photos…
CVE-2023-28784WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS)Contest Gallery
CVE-2022-45848WordPress Contest Gallery Plugin <= 13.1.0.9 is vulnerable to Cross Site Scripting (XSS)Contest Gallery
CVE-2022-4166Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4165Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4164Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4163Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4162Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4161Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4160Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4159Contest Gallery < 19.1.5.1 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4158Contest Gallery < 19.1.5 - Unauthenticated SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4157Contest Gallery < 19.1.5 - Admin+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4156Contest Gallery < 19.1.5.1 - Unauthenticated SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4155Contest Gallery < 19.1.5 - Admin+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4154Contest Gallery Pro < 19.1.5 - Admin+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4153Contest Gallery < 19.1.5.1 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4152Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4151Contest Gallery < 19.1.5 - Admin+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-4150Contest Gallery < 19.1.5 - Author+ SQL InjectionUnknown Contest Gallery Pro
CVE-2022-36394WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerabilityContest Gallery (WordPress plugin)
CVE-2022-27853WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityContest Gallery (WordPress plugin)
CVE-2021-24915Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address DisclosureUnknown Contest Gallery – Photo Contest Plugin for WordPress
CVE-2019-5974no title heldContest-Gallery Contest Gallery

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.