Extension WordPress

Vulnérabilités JoomSport – for Sports: Team & League, Football, Hockey & more

Cette page rassemble les failles publiées pour JoomSport – for Sports: Team & League, Football, Hockey & more, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
4Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de JoomSport – for Sports: Team & League, Football, Hockey & more

14 fiches

CVE-2026-13010 Moyenne · 6,5
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.7.9 – Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on…

Versions affectées

*-5.7.9

Correctif

5.7.10

Publication

09/07/2026

CVE-2026-12134 Moyenne · 4,3
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.7.8 – Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that…

Versions affectées

*-5.7.8

Correctif

5.7.9

Publication

01/07/2026

CVE-2026-12133 Moyenne · 4,3
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.7.8 – Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability…

Versions affectées

*-5.7.8

Correctif

5.7.9

Publication

30/06/2026

CVE-2026-6929 Élevée · 7,5
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.7.7 – Unauthenticated SQL Injection via 'sortf' Parameter

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping…

Versions affectées

*-5.7.7

Correctif

5.7.8

Publication

12/05/2026

CVE-2026-42647 Élevée · 7,5
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 – Unauthenticated SQL Injection

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-5.7.7

Correctif

5.7.8

Publication

29/04/2026

CVE-2024-12633 Élevée · 7,1
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.6.17 – Reflected Cross-Site Scripting via page

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization…

Versions affectées

*-5.6.17

Correctif

5.6.18

Publication

06/01/2025

CVE-2024-44031 Moyenne · 4,3
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.6.3 – Missing Authorization

The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_create_tlslider() function in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-5.6.3

Correctif

5.6.4

Publication

24/09/2024

CVE-2024-43355 Moyenne · 4,3
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport <= 5.3.0 – Missing Authorization

The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_update_option and joomsport_senddeactivation functions in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers,…

Versions affectées

*-5.3.0

Correctif

5.5.7

Publication

16/08/2024

CVE-2022-2718 Élevée · 7,2
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 – Authenticated (Admin+) SQL Injection via orderby

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient…

Versions affectées

*-5.2.5

Correctif

5.2.6

Publication

08/08/2022

CVE-2022-2717 Élevée · 7,2
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 – Authentciated (Admin+) SQL Injection via orderby

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient…

Versions affectées

*-5.2.5

Correctif

5.2.6

Publication

08/08/2022

CVE-2021-24384 Critique · 9,8
JoomSport – for Sports: Team & League, Football, Hockey & more

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 – Object Injection

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does…

Versions affectées

[*, 5.1.8)

Correctif

5.1.8

Publication

08/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités