Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contest Gallery

First CVE: Nov 29, 2021Active for: 5 yearsTotal CVEs: 38

Contest Gallery is a web-based application for managing photography contests and submissions, presenting a narrow but more prominent-than-typical exposure footprint focused on this single product line. The vendor's vulnerability disclosures center durably on SQL injection weaknesses in query handling and data validation, reflecting the application's reliance on database interactions for contest and submission management. Defenders deploying this application should prioritize input-validation and parameterized-query review as part of their security hardening; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contest Gallery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2019
7 years ago
Most Recent CVE
May 8, 2025
444 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24915CRITICAL
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a
Nov 29, 20219.848NOYES
CVE-2024-43283HIGH
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: f
Aug 26, 20247.532NOYES
CVE-2024-10687CRITICAL
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-b
Nov 5, 20249.829NONO
CVE-2024-11103CRITICAL
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not prop
Nov 28, 20249.828NONO
CVE-2019-5974HIGH
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified v
Jul 5, 20198.828NONO
CVE-2022-36394HIGH
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
Aug 23, 20228.827NONO
CVE-2024-30236CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.Th
Mar 28, 20249.925NONO
CVE-2022-4158HIGH
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an
Dec 26, 20227.525NONO
CVE-2022-4156HIGH
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQ
Dec 26, 20227.525NONO
CVE-2024-32778HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This iss
Jun 9, 20248.124NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
66%
24%
11%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None26 (68.4%)
Unknown0 (0.0%)
Required12 (31.6%)
Privileges Required
Low18 (47.4%)
High6 (15.8%)
None14 (36.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contest Gallery.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contest Gallery — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contest Gallery's Products

View all 4 CNAs →

Top CWEs