Extension WordPress

Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 3

Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.

59Vulnérabilités
5Critiques
59Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

59 fiches

CVE-2022-4162 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_row

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_row parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4165 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_order

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_order parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4152 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id GET

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id GET parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4161 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_start

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_start parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4160 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_copy_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4164 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_multiple_files_for_post

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_multiple_files_for_post parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4155 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via wp_user_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4157 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_option_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_option_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4156 Élevée · 8,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.5 – Unauthenticated SQL Injection via user_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied user_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.5

Correctif

19.1.5.1

Publication

05/12/2022

CVE-2022-4158 Élevée · 8,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Unauthenticated SQL Injection via cg_Fields

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_Fields parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

05/12/2022

CVE-2022-4163 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_activate and cg_deactivate parameters and lack of sufficient preparation on the existing…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

29/11/2022

CVE-2022-4151 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 19.1.4.1 – Authenticated (Author+) SQL Injection via option_id

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-19.1.4.1

Correctif

19.1.5

Publication

29/11/2022

CVE-2022-45848 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 13.1.0.9 – Cross-Site Scripting

The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-13.1.0.9

Correctif

14.0.0

Publication

23/11/2022

CVE-2022-36394 Élevée · 8,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 17.0.4 – Authenticated (Author+) SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 17.0.4 due to insufficient escaping on the user supplied $id parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-17.0.4

Correctif

17.0.5

Publication

09/08/2022

Vulnérabilité Élevée · 7,2
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 – Admin+ SQL Injection

The Contest Gallery – Files Upload and Contest Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the ID variable supplied via the post_contest_gallery_action_ajax AJAX action. This can only be exploited by administrative-level users and…

Versions affectées

*-17.0.4

Correctif

17.0.5

Publication

01/06/2022

CVE-2021-24915 Critique · 9,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 – SQL Injection

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated…

Versions affectées

*-13.1.0.5

Correctif

13.1.0.6

Publication

13/04/2022

Vulnérabilité Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery < 13.1.0.7 – Authenticated Email Address Disclosure

The Contest Gallery plugin for WordPress is vulnerable to Sensitive Data Exposure in versions before 13.1.0.7 via the cg_remove_not_required_coded_csvs function due to insufficient capability checks. This makes it possible for authenticated attackers with subscriber-level privileges and above to…

Versions affectées

[*, 13.1.0.7)

Correctif

13.1.0.7

Publication

01/11/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités