Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Contest Gallery — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in Contest Gallery, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the vendor-provided software component, Contest Gallery, which is tagged as a web application weakness type. The collection gathers known security flaws, including memory corruption, input validation errors, and privilege escalation issues, covering advisories published over the past five years. Visitors can track a vendor's security advisories, understand a specific weakness class, and look up the product's full vulnerability history. This aggregation serves as a central reference for security researchers, developers, and system administrators seeking to assess risk and remediation status for this specific product line. The data is organized to facilitate trend analysis and comparative review without requiring external database access.

Vendor: Contest-Gallery

CVE ID Title CVSS Severity Published
CVE-2026-61986 WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-08-19
CVE-2026-16055 Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login - - 2026-08-05
CVE-2026-16056 Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts - - 2026-08-04
CVE-2026-16057 Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library - - 2026-08-03
CVE-2026-65447 WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-27
CVE-2026-57662 WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability CWE-89 8.5 High 2026-06-26
CVE-2026-42660 WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability CWE-497 6.5 Medium 2026-06-15
CVE-2026-42657 WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability CWE-1284 6.5 Medium 2026-06-15
CVE-2026-42656 WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-06-15
CVE-2026-40771 WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-06-15
CVE-2026-25035 WordPress Contest Gallery plugin <= 28.1.2.2 - Account Takeover vulnerability CWE-288 9.8 Critical 2026-03-25
CVE-2026-24964 WordPress Contest Gallery plugin <= 28.1.2.1 - Server Side Request Forgery (SSRF) vulnerability CWE-918 6.4 Medium 2026-03-25
CVE-2026-24965 WordPress Contest Gallery plugin <= 28.1.1 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-02-03
CVE-2025-62950 WordPress Contest Gallery plugin <= 28.0.0 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-11-06
CVE-2025-48291 WordPress Contest Gallery <= 26.0.6 - Cross Site Scripting (XSS) Vulnerability CWE-79 7.1 High 2025-07-16
CVE-2025-22693 WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability CWE-89 7.6 High 2025-02-03
CVE-2024-56237 WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2025-01-02
CVE-2024-43283 WordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability CWE-201 5.3 Medium 2024-08-26
CVE-2024-39631 WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-08-01
CVE-2024-32778 WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability CWE-22 8.5 High 2024-06-09
CVE-2024-30428 WordPress Contest Gallery plugin <= 24.0.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-29
CVE-2024-30236 WordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerability CWE-89 8.5 High 2024-03-28
CVE-2024-30238 WordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerability CWE-89 8.5 High 2024-03-27
CVE-2023-28784 WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-06-22
CVE-2022-4160 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 - 2022-12-26
CVE-2022-4151 Contest Gallery < 19.1.5 - Admin+ SQL Injection 6.5 - 2022-12-26
CVE-2022-4159 Contest Gallery < 19.1.5.1 - Author+ SQL Injection 6.5 - 2022-12-26
CVE-2022-4152 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 - 2022-12-26
CVE-2022-4162 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 - 2022-12-26
CVE-2022-4164 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 - 2022-12-26

All 42 known CVE vulnerabilities affecting Contest Gallery with full Chinese analysis, references, and POCs where available.