Extension WordPress

Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 2

Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.

59Vulnérabilités
5Critiques
59Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

59 fiches

CVE-2025-1513 Élevée · 7,2
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 – Unauthenticated Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting…

Versions affectées

*-26.0.0.1

Correctif

26.0.1

Publication

27/02/2025

CVE-2025-22693 Moyenne · 6,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 25.1.0 – Authenticated (Author+) SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 25.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

Versions affectées

*-25.1.0

Correctif

25.1.2

Publication

31/01/2025

CVE-2024-56237 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 24.0.3 – Authenticated (Author+) Stored Cross-Site Scripting

The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 24.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…

Versions affectées

*-24.0.3

Correctif

24.0.4

Publication

30/12/2024

CVE-2024-11103 Critique · 9,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 24.0.7 – Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their…

Versions affectées

*-24.0.7

Correctif

24.0.8

Publication

27/11/2024

CVE-2024-10687 Critique · 9,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 – Unauthenticated SQL Injection

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and…

Versions affectées

*-24.0.3

Correctif

24.0.4

Publication

04/11/2024

CVE-2024-43283 Moyenne · 5,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 23.1.2 – Unauthenticated Information Exposure

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 23.1.2. This makes…

Versions affectées

*-23.1.2

Correctif

23.1.3

Publication

16/08/2024

CVE-2024-39631 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 23.1.2 – Unauthenticated Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 23.1.2 due to…

Versions affectées

*-23.1.2

Correctif

23.1.3

Publication

24/07/2024

CVE-2024-32778 Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 21.3.4 – Authenticated (Author+) Arbitrary File Deletion

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on a function…

Versions affectées

*-21.3.4

Correctif

21.3.5

Publication

22/04/2024

CVE-2024-30428 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 21.3.5 – Reflected Cross-Site Scripting

The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 21.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-21.3.5

Correctif

21.3.6

Publication

28/03/2024

CVE-2024-30238 Critique · 9,9
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos and Files Contest Gallery <= 21.3.2 – Authenticated (Contributor+) SQL Injection

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 21.3.2 due to insufficient…

Versions affectées

*-21.3.2

Correctif

21.3.2.1

Publication

26/03/2024

CVE-2024-30236 Critique · 9,9
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos and Files Contest Gallery <= 21.3.4 – Authenticated (Contributor+) SQL Injection

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 21.3.4 due to insufficient…

Versions affectées

*-21.3.4

Correctif

21.3.5

Publication

26/03/2024

CVE-2024-1487 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 – Authenticated (Author+) Stored Cross-Site Scripting

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 21.3.0 due to…

Versions affectées

*-21.3.0

Correctif

21.3.1

Publication

14/02/2024

CVE-2024-24887 Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 21.2.8.4 – Cross-Site Request Forgery

The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.2.8.4. This is due to missing or incorrect nonce validation in the prev10/prev10-admin/gallery/gallery.php file. This makes it possible for unauthenticated…

Versions affectées

*-21.2.8.4

Correctif

21.2.9

Publication

05/02/2024

Vulnérabilité Moyenne · 4,7
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 21.2.8.4 – Cross-Site Request Forgery

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.2.8.4. This is due…

Versions affectées

*-21.2.8.4

Correctif

21.2.9

Publication

09/01/2024

CVE-2023-5307 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery < 21.2.8.1 – Unauthenticated Stored Cross-Site Scripting via headers

The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via headers in all versions up to 21.2.8.1 (exclusive) due to…

Versions affectées

[*, 21.2.8.1)

Correctif

21.2.8.1

Publication

10/10/2023

CVE-2023-28784 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 21.1.2 – Reflected Cross-Site Scripting

The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 21.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-21.1.2

Correctif

21.1.2.1

Publication

27/03/2023

CVE-2022-4166 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via addCountS

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied addCountS parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4150 Élevée · 8,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery (Pro) <= 19.1.5 – SQL Injection via option_id

The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-19.1.5

Correctif

19.1.5.1

Publication

05/12/2022

CVE-2022-4153 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via upload[]

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied upload[] parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.5

Correctif

19.1.5.1

Publication

05/12/2022

CVE-2022-4159 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via cg_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied cg_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.5

Correctif

19.1.5.1

Publication

05/12/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités