CVE-2025-22693

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This issue affects Contest Gallery: from n/a through <= 25.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:*:wordpress:*:*

History

01 Apr 2026, 16:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 7.2
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-25-1-0-sql-injection-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-25-1-0-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery Contest Gallery allows SQL Injection. This issue affects Contest Gallery: from n/a through 25.1.0. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This issue affects Contest Gallery: from n/a through <= 25.1.0.

15 Apr 2025, 19:58

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Contest Gallery Contest Gallery permite la inyección SQL. Este problema afecta a Contest Gallery: desde n/a hasta 25.1.0.
CPE cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:*:wordpress:*:*
References () https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-25-1-0-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-25-1-0-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
First Time Contest-gallery contest Gallery
Contest-gallery

03 Feb 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 15:15

Updated : 2026-04-01 16:22


NVD link : CVE-2025-22693

Mitre link : CVE-2025-22693

CVE.ORG link : CVE-2025-22693


JSON object : View

Products Affected

contest-gallery

  • contest_gallery
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')