Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the Contest Gallery WordPress plugin, specifically focusing on weaknesses within the upload, voting, and payment processing functionalities. It aggregates disclosed security issues related to this vendor's product, covering reports from its initial public availability through to the most recent advisory updates. By consolidating these findings, the page serves as a centralized reference for tracking the vendor's response to security incidents and understanding the evolution of risks in their codebase. Readers can discover the history of specific vulnerability classes, such as cross-site scripting or insecure direct object references, within the context of the Contest Gallery application. This resource allows security professionals and site administrators to investigate how the developer has addressed past flaws and to assess the overall security posture of the software over time. Users can look up the product's vulnerability history to identify recurring patterns or critical failures in input validation and authentication mechanisms. The collection includes data on how the vendor has patched these weaknesses and the timelines of their respective disclosures. This information is vital for evaluating the reliability of the plugin in commercial environments where sensitive user data and payment transactions are handled. By reviewing these aggregated records, stakeholders can make informed decisions about the safety of integrating this media and contest management tool into their web infrastructure, ensuring that known risks are mitigated before deployment.

Vendor: contest-gallery

CVE IDTitleCVSSSeverityPublished
CVE-2026-16586 Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' CWE-89 6.5 Medium2026-08-15
CVE-2026-12165 Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter CWE-269 8.8 High2026-06-17
CVE-2026-8912 Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection CWE-89 7.5 High2026-05-19
CVE-2026-4021 Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion CWE-287 8.1 High2026-03-23
CVE-2026-3180 Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection CWE-89 7.5 High2026-03-02
CVE-2025-12849 Contest Gallery <= 28.0.2 - Missing Authorization CWE-862 5.3 Medium2025-11-15
CVE-2025-11254 Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection CWE-1236 4.3 Medium2025-10-11
CVE-2025-10383 Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-10-04
CVE-2025-7725 Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-08-01
CVE-2025-6716 Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-07-11
CVE-2025-3862 Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium2025-05-08
CVE-2025-1513 Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-02-28
CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover CWE-640 9.8 Critical2024-11-28
CVE-2024-10687 Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection CWE-89 9.8 Critical2024-11-05

All 14 known CVE vulnerabilities affecting Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe with full Chinese analysis, references, and POCs where available.