Beardev
Beardev Joomsport: vulnerabilidades y CVE
Beardev Joomsport tiene 15 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses7
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11920 | Media (4.9) | 0.48% | — | 5 ago 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient… |
| CVE-2026-13010 | Media (6.5) | 0.41% | — | 10 jul 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to… |
| CVE-2026-12134 | Media (4.3) | 0.40% | — | 2 jul 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying… |
| CVE-2026-12133 | Media (4.3) | 0.43% | — | 1 jul 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a… |
| CVE-2026-42647 | Crítica (9.3) | 1.3% | — | 11 jun 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7. |
| CVE-2026-6929 | Alta (7.5) | 0.54% | — | 13 may 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to… |
| CVE-2025-7721 | Crítica (9.8) | 0.66% | — | 3 oct 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible… |
| CVE-2024-12633 | Alta (7.1) | 0.29% | — | 7 ene 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to… |
| CVE-2024-44031 | Alta (8.8) | 0.36% | — | 1 nov 2024 | Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects JoomSport: from n/a through <= 5.6.3. |
| CVE-2024-43355 | Alta (8.8) | 0.42% | — | 1 nov 2024 | Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.3.0. |
| CVE-2022-4050 | Crítica (9.8) | 4.8% | — | 19 dic 2022 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users |
| CVE-2022-2718 | Media (4.9) | 1.5% | — | 6 sept 2022 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including,… |
| CVE-2022-2717 | Media (4.9) | 1.5% | — | 6 sept 2022 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including,… |
| CVE-2021-24384 | Crítica (9.8) | 2.1% | — | 6 jul 2021 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP… |
| CVE-2019-14348 | Crítica (9.8) | 21% | — | 5 ago 2019 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter. |