CVE-2026-78088Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter Exploitation status Not confirmed Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 09/16/2026 Severity High CVE-2026-16586Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 08/15/2026 Severity Medium CVE-2026-12165Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 06/17/2026 Severity High CVE-2026-8912Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 05/19/2026 Severity High CVE-2026-4021Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 03/23/2026 Severity High CVE-2026-3180Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 03/02/2026 Severity High CVE-2025-12849Contest Gallery <= 28.0.2 - Missing Authorization Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 11/15/2025 Severity Medium CVE-2025-11254Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 10/11/2025 Severity Medium CVE-2025-10383Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 10/04/2025 Severity Medium CVE-2025-7725Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 08/01/2025 Severity High CVE-2025-6716Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 07/11/2025 Severity Medium CVE-2025-3862Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 05/08/2025 Severity Medium CVE-2025-1513Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 02/28/2025 Severity High CVE-2025-22693WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 02/03/2025 Severity High CVE-2024-56237WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 01/02/2025 Severity Medium CVE-2024-11103Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 11/28/2024 Severity Critical CVE-2024-10687Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection Exploitation status Not known exploited Fix YesAffected product C Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Published 11/05/2024 Severity Critical CVE-2024-43283WordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 08/26/2024 Severity Medium CVE-2024-39631WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 08/01/2024 Severity High CVE-2024-32778WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 06/09/2024 Severity High CVE-2024-30428WordPress Contest Gallery plugin <= 24.0.3 - Reflected Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 03/29/2024 Severity High CVE-2024-30236WordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 03/28/2024 Severity High CVE-2024-30238WordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 03/27/2024 Severity High CVE-2024-1487Photos and Files Contest Gallery < 21.3.1 - Author+ Stored Cross Site Scripting Exploitation status Public exploit Fix YesAffected product P Photos and Files Contest Gallery Published 03/11/2024 Severity Medium CVE-2024-24887WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) Exploitation status Not known exploited Fix YesAffected product P Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress Published 02/12/2024 Severity Medium CVE-2023-5307Photos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP Headers Exploitation status Public exploit Fix YesAffected product P Photos and Files Contest Gallery Published 10/31/2023 Severity Medium CVE-2023-28784WordPress Contest Gallery Plugin <= 21.1.2 is vulnerable to Cross Site Scripting (XSS) Exploitation status Not known exploited Fix YesAffected product C Contest Gallery Published 06/22/2023 Severity High CVE-2022-4160Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4151Contest Gallery < 19.1.5 - Admin+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4159Contest Gallery < 19.1.5.1 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4152Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4162Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4164Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4156Contest Gallery < 19.1.5.1 - Unauthenticated SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity High CVE-2022-4154Contest Gallery Pro < 19.1.5 - Admin+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Pro Published 12/26/2022 Severity Medium CVE-2022-4163Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4166Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4150Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4158Contest Gallery < 19.1.5 - Unauthenticated SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity High CVE-2022-4165Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4155Contest Gallery < 19.1.5 - Admin+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4157Contest Gallery < 19.1.5 - Admin+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4153Contest Gallery < 19.1.5.1 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-4161Contest Gallery < 19.1.5 - Author+ SQL Injection Exploitation status Public exploit Fix YesAffected product C Contest Gallery Published 12/26/2022 Severity Medium CVE-2022-45848WordPress Contest Gallery Plugin <= 13.1.0.9 is vulnerable to Cross Site Scripting (XSS) Exploitation status Not confirmed Fix YesAffected product C Contest Gallery Published 12/06/2022 Severity Medium CVE-2022-36394WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery (WordPress plugin) Published 08/23/2022 Severity High CVE-2022-27853WordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product C Contest Gallery (WordPress plugin) Published 04/18/2022 Severity Medium CVE-2019-5974Exploitation status Not confirmed Fix Not confirmed Affected product C Contest Gallery Published 07/05/2019 Severity Unknown