Extension WordPress
Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, page 4
Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
64 fiches
Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 – SQL Injection
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated…
*-13.1.0.5
13.1.0.6
13/04/2022
Contest Gallery <= 13.1.0.9 – Authenticated (Author+) Stored Cross-Site Scripting
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin)
*-13.1.0.9
14.0.0
20/12/2021
Contest Gallery < 13.1.0.7 – Authenticated Email Address Disclosure
The Contest Gallery plugin for WordPress is vulnerable to Sensitive Data Exposure in versions before 13.1.0.7 via the cg_remove_not_required_coded_csvs function due to insufficient capability checks. This makes it possible for authenticated attackers with subscriber-level privileges and above to…
[*, 13.1.0.7)
13.1.0.7
01/11/2021
Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
*-10.4.4
10.4.5
12/06/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.