Vulnerabilities > Contest Gallery > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-26 CVE-2022-4159 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4160 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4161 SQL Injection vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php.
network
low complexity
contest-gallery CWE-89
6.5
2022-12-26 CVE-2022-4162 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4163 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4164 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4165 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php.
network
low complexity
contest-gallery
6.5
2022-12-26 CVE-2022-4166 Unspecified vulnerability in Contest-Gallery Contest Gallery
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php.
network
low complexity
contest-gallery
6.5
2022-12-06 CVE-2022-45848 Cross-site Scripting vulnerability in Contest-Gallery Contest Gallery
Unauth.
network
low complexity
contest-gallery CWE-79
6.1
2019-07-05 CVE-2019-5974 Cross-Site Request Forgery (CSRF) vulnerability in Contest-Gallery Contest Gallery
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
6.8