Extension WordPress
Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 2
Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
59 fiches
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 – Unauthenticated Stored Cross-Site Scripting
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting…
*-26.0.0.1
26.0.1
27/02/2025
Contest Gallery <= 25.1.0 – Authenticated (Author+) SQL Injection
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 25.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-25.1.0
25.1.2
31/01/2025
Contest Gallery <= 24.0.3 – Authenticated (Author+) Stored Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 24.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…
*-24.0.3
24.0.4
30/12/2024
Contest Gallery <= 24.0.7 – Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their…
*-24.0.7
24.0.8
27/11/2024
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 – Unauthenticated SQL Injection
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and…
*-24.0.3
24.0.4
04/11/2024
Contest Gallery <= 23.1.2 – Unauthenticated Information Exposure
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 23.1.2. This makes…
*-23.1.2
23.1.3
16/08/2024
Contest Gallery <= 23.1.2 – Unauthenticated Stored Cross-Site Scripting
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 23.1.2 due to…
*-23.1.2
23.1.3
24/07/2024
Contest Gallery <= 21.3.4 – Authenticated (Author+) Arbitrary File Deletion
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on a function…
*-21.3.4
21.3.5
22/04/2024
Contest Gallery <= 21.3.5 – Reflected Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 21.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-21.3.5
21.3.6
28/03/2024
Photos and Files Contest Gallery <= 21.3.2 – Authenticated (Contributor+) SQL Injection
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 21.3.2 due to insufficient…
*-21.3.2
21.3.2.1
26/03/2024
Photos and Files Contest Gallery <= 21.3.4 – Authenticated (Contributor+) SQL Injection
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 21.3.4 due to insufficient…
*-21.3.4
21.3.5
26/03/2024
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 – Authenticated (Author+) Stored Cross-Site Scripting
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 21.3.0 due to…
*-21.3.0
21.3.1
14/02/2024
Contest Gallery <= 21.2.8.4 – Cross-Site Request Forgery
The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.2.8.4. This is due to missing or incorrect nonce validation in the prev10/prev10-admin/gallery/gallery.php file. This makes it possible for unauthenticated…
*-21.2.8.4
21.2.9
05/02/2024
Contest Gallery <= 21.2.8.4 – Cross-Site Request Forgery
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.2.8.4. This is due…
*-21.2.8.4
21.2.9
09/01/2024
Contest Gallery < 21.2.8.1 – Unauthenticated Stored Cross-Site Scripting via headers
The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via headers in all versions up to 21.2.8.1 (exclusive) due to…
[*, 21.2.8.1)
21.2.8.1
10/10/2023
Contest Gallery <= 21.1.2 – Reflected Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 21.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-21.1.2
21.1.2.1
27/03/2023
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via addCountS
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied addCountS parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery (Pro) <= 19.1.5 – SQL Injection via option_id
The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via upload[]
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied upload[] parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via cg_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied cg_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.