Extension WordPress
Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 3
Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
64 fiches
Contest Gallery <= 21.1.2 – Reflected Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 21.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-21.1.2
21.1.2.1
27/03/2023
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via addCountS
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied addCountS parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery (Pro) <= 19.1.5 – SQL Injection via option_id
The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via upload[]
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied upload[] parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.5 – Authenticated (Author+) SQL Injection via cg_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied cg_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_row
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_row parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_order
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_order parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id GET
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id GET parameter and lack of sufficient preparation on the existing SQL…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_start
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_start parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_multiple_files_for_post
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_multiple_files_for_post parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via wp_user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.5 – Unauthenticated SQL Injection via user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.4.1 – Unauthenticated SQL Injection via cg_Fields
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_Fields parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_activate and cg_deactivate parameters and lack of sufficient preparation on the existing…
*-19.1.4.1
19.1.5
29/11/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
29/11/2022
Contest Gallery <= 13.1.0.9 – Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-13.1.0.9
14.0.0
23/11/2022
Contest Gallery <= 17.0.4 – Authenticated (Author+) SQL Injection
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 17.0.4 due to insufficient escaping on the user supplied $id parameter and lack of sufficient preparation on the existing SQL query.…
*-17.0.4
17.0.5
09/08/2022
Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 – Admin+ SQL Injection
The Contest Gallery – Files Upload and Contest Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ID variable supplied via the post_contest_gallery_action_ajax AJAX action. This can only be exploited by administrative-level users and…
*-17.0.4
17.0.5
01/06/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.