Extension WordPress
Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 3
Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
59 fiches
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_row
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_row parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_order
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_order parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id GET
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id GET parameter and lack of sufficient preparation on the existing SQL…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_start
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_start parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_multiple_files_for_post
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_multiple_files_for_post parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via wp_user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.5 – Unauthenticated SQL Injection via user_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied user_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.5
19.1.5.1
05/12/2022
Contest Gallery <= 19.1.4.1 – Unauthenticated SQL Injection via cg_Fields
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_Fields parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
05/12/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_activate and cg_deactivate parameters and lack of sufficient preparation on the existing…
*-19.1.4.1
19.1.5
29/11/2022
Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query.…
*-19.1.4.1
19.1.5
29/11/2022
Contest Gallery <= 13.1.0.9 – Cross-Site Scripting
The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-13.1.0.9
14.0.0
23/11/2022
Contest Gallery <= 17.0.4 – Authenticated (Author+) SQL Injection
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 17.0.4 due to insufficient escaping on the user supplied $id parameter and lack of sufficient preparation on the existing SQL query.…
*-17.0.4
17.0.5
09/08/2022
Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 – Admin+ SQL Injection
The Contest Gallery – Files Upload and Contest Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ID variable supplied via the post_contest_gallery_action_ajax AJAX action. This can only be exploited by administrative-level users and…
*-17.0.4
17.0.5
01/06/2022
Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 – SQL Injection
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated…
*-13.1.0.5
13.1.0.6
13/04/2022
Contest Gallery <= 13.1.0.9 – Authenticated (Author+) Stored Cross-Site Scripting
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin)
*-13.1.0.9
14.0.0
20/12/2021
Contest Gallery < 13.1.0.7 – Authenticated Email Address Disclosure
The Contest Gallery plugin for WordPress is vulnerable to Sensitive Data Exposure in versions before 13.1.0.7 via the cg_remove_not_required_coded_csvs function due to insufficient capability checks. This makes it possible for authenticated attackers with subscriber-level privileges and above to…
[*, 13.1.0.7)
13.1.0.7
01/11/2021
Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
*-10.4.4
10.4.5
12/06/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.