CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57662HIGH | WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerabilityContributor SQL Injection in Contest Gallery <= 30.0.0 versions. CWE-89Jun 26, 2026 | CVSS8.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42660MEDIUM | WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerabilitySubscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. CWE-497Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.345% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42657MEDIUM | WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerabilityUnauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. CWE-1284Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42656MEDIUM | WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulnerabilitySubscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. CWE-79Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40771CRITICAL | WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerabilityUnauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. CWE-89Jun 15, 2026 | CVSS9.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32778HIGH | WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 21.3.4. | CVSS8.5v3.1 | EPSS0.612% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |