Pricing
Case studies
Login
Start trial
Contest Gallery
Wasiliy Strecker / ContestGallery developer
Developer
28.1.6
Latest version
1,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
34 patched
19 Mitigation rules
Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion vulnerability
<= 28.1.5
24/03/2026
Account Takeover vulnerability
<= 28.1.2.2
23/03/2026
Server Side Request Forgery (SSRF) vulnerability
<= 28.1.2.1
10/03/2026
Unauthenticated SQL Injection vulnerability
<= 28.1.4
03/03/2026
Broken Access Control vulnerability
<= 28.1.1
09/01/2026
Missing Authorization vulnerability
<= 28.0.2
14/11/2025
Cross Site Request Forgery (CSRF) vulnerability
<= 28.0.0
12/10/2025
Unauthenticated CSV Injection vulnerability
<= 27.0.3
10/10/2025
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 27.0.2
03/10/2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 26.1.0
31/07/2025
Cross Site Scripting (XSS) Vulnerability
<= 26.0.6
11/07/2025
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 26.0.8
10/07/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter vulnerability
<= 26.0.6
08/05/2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 26.0.0.1
27/02/2025
SQL Injection vulnerability
<= 25.1.0
31/01/2025
Cross Site Scripting (XSS) vulnerability
<= 24.0.3
30/12/2024
Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover vulnerability
<= 24.0.7
27/11/2024
Unauthenticated SQL Injection vulnerability
<= 24.0.3
04/11/2024
Unauthenticated Comment UserID And IP address Disclosure vulnerability
<= 23.1.2
16/08/2024
Cross Site Scripting (XSS) vulnerability
<= 23.1.2
24/07/2024
Arbitrary File Deletion vulnerability
<= 21.3.4
22/04/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 24.0.3
28/03/2024
SQL Injection vulnerability
<= 21.3.2
26/03/2024
SQL Injection vulnerability
<= 21.3.4
26/03/2024
Author+ Stored Cross Site Scripting vulnerability
< 21.3.1
12/03/2024
CSRF Leading to Gallery Creation vulnerability
<= 21.2.8.4
05/02/2024
Unauth. Stored XSS via HTTP Headers vulnerability
< 21.2.8.1
31/10/2023
Cross Site Scripting (XSS) vulnerability
<= 21.1.2
27/03/2023
Unauth. Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.0.9
23/11/2022
Authenticated SQL Injection (SQLi) vulnerability
<= 17.0.4
09/08/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.0.9
20/12/2021
Missing Access Controls to Unauthenticated SQL injection (SQLi) / Email Address Disclosure vulnerability
<= 13.1.0.5
01/11/2021
Email Address Disclosure vulnerability
<= 13.1.0.6
01/11/2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 10.4.4
10/07/2019