What is CVE-2026-65447?
This CVE-2026-65447 describes an unauthenticated Cross Site Scripting (XSS) vulnerability in the Contest Gallery plugin. It affects versions up to and including 30.0.6. Successful exploitation could allow an attacker to execute malicious scripts in a user's browser, making an immediate update to the latest version essential.
Azərbaycanca: Bu CVE-2026-65447, Contest Gallery plagini üçün autentifikasiya tələb etmədən həyata keçirilə bilən Cross Site Scripting (XSS) zəifliyidir. 30.0.6 və daha əvvəlki versiyalara təsir edir. İstismar zamanı təcavüzkar istifadəçi brauzerində xüsusi kod işlədə bilər, plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Is authentication required to exploit the CVE-2026-65447 vulnerability in the Contest Gallery plugin?
No, this is an unauthenticated Cross Site Scripting (XSS) vulnerability.
What action is recommended to protect against CVE-2026-65447 in the Contest Gallery plugin?
It is recommended to update the plugin to the latest version, as versions up to and including 30.0.6 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.