Contest-Gallery Contest Gallery vulnerabilities

37 known vulnerabilities affecting contest-gallery/contest_gallery.

Total CVEs
37
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM25

Vulnerabilities

Page 2 of 2
CVE-2022-4164MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4164 [MEDIUM] CWE-89 CVE-2022-4164: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4154MEDIUMCVSS 4.9fixed in 19.1.5.12022-12-26
CVE-2022-4154 [MEDIUM] CWE-89 CVE-2022-4154: The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.
nvd
CVE-2022-4163MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4163 [MEDIUM] CWE-89 CVE-2022-4163: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive informati
nvd
CVE-2022-4155MEDIUMCVSS 4.9fixed in 19.1.5.12022-12-26
CVE-2022-4155 [MEDIUM] CWE-89 CVE-2022-4155: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information
nvd
CVE-2022-4162MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4162 [MEDIUM] CWE-89 CVE-2022-4162: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4150MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4150 [MEDIUM] CWE-89 CVE-2022-4150: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's data
nvd
CVE-2022-4157MEDIUMCVSS 4.9fixed in 19.1.5.12022-12-26
CVE-2022-4157 [MEDIUM] CWE-89 CVE-2022-4157: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information
nvd
CVE-2022-4161MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4161 [MEDIUM] CWE-89 CVE-2022-4161: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4160MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4160 [MEDIUM] CWE-89 CVE-2022-4160: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's databas
nvd
CVE-2022-4152MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4152 [MEDIUM] CWE-89 CVE-2022-4152: The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1 The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4166MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4166 [MEDIUM] CWE-89 CVE-2022-4166: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4151MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4151 [MEDIUM] CWE-89 CVE-2022-4151: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-4159MEDIUMCVSS 6.5fixed in 19.1.5.12022-12-26
CVE-2022-4159 [MEDIUM] CWE-89 CVE-2022-4159: The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19 The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
nvd
CVE-2022-45848MEDIUMCVSS 6.1≤ 13.1.0.92022-12-06
CVE-2022-45848 [MEDIUM] CWE-79 CVE-2022-45848: Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on Wor Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
nvd
CVE-2022-36394HIGHCVSS 8.8≤ 17.0.42022-08-23
CVE-2022-36394 [HIGH] CWE-89 CVE-2022-36394: Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at Wo Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
nvd
CVE-2022-27853MEDIUMCVSS 4.8≤ 13.1.0.92022-04-18
CVE-2022-27853 [MEDIUM] CWE-79 CVE-2022-27853: Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPres Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9
nvd
CVE-2019-5974HIGHCVSS 8.8fixed in 10.4.5vversions prior to 10.4.52019-07-05
CVE-2019-5974 [HIGH] CWE-352 CVE-2019-5974: Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows r Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
cvelistv5nvd