Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Contest Gallery — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in Contest Gallery, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses for the Contest Gallery product, provided by various vendors under the general category of software vulnerability aggregation. It compiles a comprehensive list of disclosed issues affecting this application, ranging from critical remote code execution flaws to lower-severity information disclosure bugs. The data covers vulnerabilities identified and reported between the years 2018 and 2023, ensuring a broad historical perspective on the product's security landscape. Visitors can utilize this resource to track specific vendor advisories and monitor how different security teams have responded to similar threats over time. Additionally, users can gain a deeper understanding of common weakness classifications, such as injection attacks or improper access control, as they relate to contest management platforms. The page also allows for a detailed lookup of a specific product’s vulnerability history, enabling developers and security analysts to assess long-term stability and remediation efforts. By reviewing these aggregated records, stakeholders can identify patterns in defect types and prioritize patching strategies accordingly. This approach fosters transparency and helps organizations mitigate risks associated with third-party components. The content is organized to facilitate quick reference and deep analysis, supporting informed decision-making for system administrators and security engineers. No specific CVE identifiers are highlighted here to maintain a focus on the structural and categorical aspects of the flaws rather than individual incident details. This holistic view aids in proactive security planning and reinforces the importance of continuous monitoring.

Vendor: Contest-Gallery

CVE IDTitleCVSSSeverityPublished
CVE-2026-57662 WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability CWE-89 8.5 High2026-06-26
CVE-2026-42660 WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability CWE-497 6.5 Medium2026-06-15
CVE-2026-42657 WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability CWE-1284 6.5 Medium2026-06-15
CVE-2026-42656 WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-06-15
CVE-2026-40771 WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerability CWE-89 9.3 Critical2026-06-15
CVE-2026-25035 WordPress Contest Gallery plugin <= 28.1.2.2 - Account Takeover vulnerability CWE-288 9.8 Critical2026-03-25
CVE-2026-24964 WordPress Contest Gallery plugin <= 28.1.2.1 - Server Side Request Forgery (SSRF) vulnerability CWE-918 6.4 Medium2026-03-25
CVE-2026-24965 WordPress Contest Gallery plugin <= 28.1.1 - Broken Access Control vulnerability CWE-862 4.3 Medium2026-02-03
CVE-2025-62950 WordPress Contest Gallery plugin <= 28.0.0 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2025-11-06
CVE-2025-48291 WordPress Contest Gallery <= 26.0.6 - Cross Site Scripting (XSS) Vulnerability CWE-79 7.1 High2025-07-16
CVE-2025-22693 WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability CWE-89 7.6 High2025-02-03
CVE-2024-56237 WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium2025-01-02
CVE-2024-43283 WordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability CWE-201 5.3 Medium2024-08-26
CVE-2024-39631 WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-08-01
CVE-2024-32778 WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability CWE-22 8.5 High2024-06-09
CVE-2024-30428 WordPress Contest Gallery plugin <= 24.0.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-29
CVE-2024-30236 WordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerability CWE-89 8.5 High2024-03-28
CVE-2024-30238 WordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerability CWE-89 8.5 High2024-03-27
CVE-2023-28784 WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-06-22
CVE-2022-4160 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4151 Contest Gallery < 19.1.5 - Admin+ SQL Injection 6.5 -2022-12-26
CVE-2022-4159 Contest Gallery < 19.1.5.1 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4152 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4162 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4164 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4156 Contest Gallery < 19.1.5.1 - Unauthenticated SQL Injection 6.5 -2022-12-26
CVE-2022-4163 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4150 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4166 Contest Gallery < 19.1.5 - Author+ SQL Injection 6.5 -2022-12-26
CVE-2022-4158 Contest Gallery < 19.1.5 - Unauthenticated SQL Injection 7.5 -2022-12-26

All 37 known CVE vulnerabilities affecting Contest Gallery with full Chinese analysis, references, and POCs where available.