Skip to content

Known CVE

Contest Gallery < 13.1.0.6 - SQL injection

The plugin does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address.

CVE-2021-24915

Critical2021CVSS 9.8CWE-89

cve2021 · wordpress · wp-plugin · wpscan · wp · contest-gallery · contest_gallery · sqli

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website