Export limit exceeded: 360100 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-1487 | 1 Contest-gallery | 1 Contest Gallery | 2025-04-01 | 5.4 Medium |
| The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks. | ||||
| CVE-2022-27853 | 1 Contest-gallery | 1 Contest Gallery | 2025-02-20 | 4.8 Medium |
| Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.9 | ||||
| CVE-2022-36394 | 1 Contest-gallery | 1 Contest Gallery | 2025-02-20 | 7.6 High |
| Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. | ||||
| CVE-2023-28784 | 1 Contest-gallery | 1 Contest Gallery | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions. | ||||
| CVE-2022-45848 | 1 Contest-gallery | 1 Contest Gallery | 2024-11-21 | 6.1 Medium |
| Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. | ||||
| CVE-2019-5974 | 1 Contest-gallery | 1 Contest Gallery | 2024-11-21 | N/A |
| Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||||