Vulnerabilities > Contest Gallery > Contest Gallery > 21.1.2.5

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-5307 Cross-site Scripting vulnerability in Contest-Gallery Contest Gallery
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
network
low complexity
contest-gallery CWE-79
6.1