Contest Gallery is a web-based application for managing photography contests and submissions, presenting a narrow but more prominent-than-typical exposure footprint focused on this single product line. The vendor's vulnerability disclosures center durably on SQL injection weaknesses in query handling and data validation, reflecting the application's reliance on database interactions for contest and submission management. Defenders deploying this application should prioritize input-validation and parameterized-query review as part of their security hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contest Gallery over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24915CRITICAL The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a | Nov 29, 2021 | 9.8 | 48 | NO | YES |
CVE-2024-43283HIGH Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: f | Aug 26, 2024 | 7.5 | 32 | NO | YES |
CVE-2024-10687CRITICAL The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-b | Nov 5, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-11103CRITICAL The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not prop | Nov 28, 2024 | 9.8 | 28 | NO | NO |
CVE-2019-5974HIGH Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified v | Jul 5, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-36394HIGH Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. | Aug 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-30236CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.Th | Mar 28, 2024 | 9.9 | 25 | NO | NO |
CVE-2022-4158HIGH The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-4156HIGH The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQ | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-32778HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This iss | Jun 9, 2024 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contest Gallery.
Media articles that mention a CVE ID that affects a product developed by Contest Gallery — matched by CVE ID, not by vendor name.