Known vulnerabilities in the Contest Gallery plugin
24 security advisories have been published for the Contest Gallery plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2026-61986) HIGH
- Contest Gallery - SQL Injection (CVE-2026-16586) MEDIUM
- Contest Gallery - Security Vulnerability (CVE-2026-16055) HIGH
- Contest Gallery - Cross-Site Request Forgery (CSRF) (CVE-2026-16056) MEDIUM
- Contest Gallery - Cross-Site Request Forgery (CSRF) (CVE-2026-16057) MEDIUM
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2026-65447) HIGH
- Contest Gallery - SQL Injection (CVE-2026-57662) HIGH
- Contest Gallery - Privilege Escalation (CVE-2026-12165) HIGH
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2026-42656) MEDIUM
- Contest Gallery - SQL Injection (CVE-2026-40771) CRITICAL
- Contest Gallery - SQL Injection (CVE-2026-8912) HIGH
- Contest Gallery - Authentication Bypass (CVE-2026-4021) HIGH
- Contest Gallery - SQL Injection (CVE-2026-3180) HIGH
- Contest Gallery - Broken Access Control (CVE-2025-12849) MEDIUM
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2025-10383) MEDIUM
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2025-3862) MEDIUM
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2025-1513) HIGH
- Contest Gallery - Privilege Escalation (CVE-2024-11103) CRITICAL
- Contest Gallery - SQL Injection (CVE-2024-10687) CRITICAL
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2024-1487) MEDIUM
- Contest Gallery - Cross-Site Request Forgery (CSRF) (CVE-2024-24887) MEDIUM
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2023-5307) MEDIUM
- Contest Gallery - SQL Injection (CVE-2022-36394) HIGH
- Contest Gallery - Cross-Site Scripting (XSS) (CVE-2021-24915) CRITICAL