Extension WordPress
Vulnérabilités Contest Gallery Pro
Cette page rassemble les failles publiées pour Contest Gallery Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contest Gallery Pro
18 fiches
Contest Gallery Pro <= 29.0.1 – Unauthenticated Privilege Escalation
The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 29.0.1. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
*-29.0.1
29.0.2
17/05/2026
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via addCountS
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied addCountS parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery (Pro) <= 19.1.5 – SQL Injection via option_id
The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via upload[]
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied upload[] parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via cg_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied cg_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_row
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_row parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_order
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_order parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id GET
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id GET parameter and lack of sufficient preparation on the existing SQL…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery Pro <= 19.1.4.1 – Authenticated (Administrator+) SQL Injection via wp_user_id
The Contest Gallery Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_start
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_start parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_multiple_files_for_post
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_multiple_files_for_post parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via wp_user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.5 – Unauthenticated SQL Injection via user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.4.1 – Unauthenticated SQL Injection via cg_Fields
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_Fields parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_activate and cg_deactivate parameters and lack of sufficient preparation on the existing…
*-19.1.4.1
19.1.5
29/11/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
29/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.