Extension WordPress
Vulnérabilités JoomSport – for Sports: Team & League, Football, Hockey & more
Cette page rassemble les failles publiées pour JoomSport – for Sports: Team & League, Football, Hockey & more, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de JoomSport – for Sports: Team & League, Football, Hockey & more
14 fiches
JoomSport <= 5.7.9 – Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on…
*-5.7.9
5.7.10
09/07/2026
JoomSport <= 5.7.8 – Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that…
*-5.7.8
5.7.9
01/07/2026
JoomSport <= 5.7.8 – Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability…
*-5.7.8
5.7.9
30/06/2026
JoomSport <= 5.7.7 – Unauthenticated SQL Injection via 'sortf' Parameter
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping…
*-5.7.7
5.7.8
12/05/2026
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 – Unauthenticated SQL Injection
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack…
*-5.7.7
5.7.8
29/04/2026
JoomSport <= 5.7.3 – Unauthenticated Directory Traversal to Local File Inclusion
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for…
*-5.7.3
5.7.4
03/10/2025
JoomSport <= 5.6.17 – Reflected Cross-Site Scripting via page
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization…
*-5.6.17
5.6.18
06/01/2025
JoomSport <= 5.6.3 – Missing Authorization
The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_create_tlslider() function in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with subscriber-level…
*-5.6.3
5.6.4
24/09/2024
JoomSport <= 5.3.0 – Missing Authorization
The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_update_option and joomsport_senddeactivation functions in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers,…
*-5.3.0
5.5.7
16/08/2024
JoomSport <= 5.2.7 – Unauthenticated SQL Injection
The JoomSport plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.2.7
5.2.8
28/11/2022
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 – Authenticated (Admin+) SQL Injection via orderby
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient…
*-5.2.5
5.2.6
08/08/2022
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 – Authentciated (Admin+) SQL Injection via orderby
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient…
*-5.2.5
5.2.6
08/08/2022
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 – Object Injection
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does…
[*, 5.1.8)
5.1.8
08/06/2021
JoomSport – for Sports: Team & League, Football, Hockey & more < 3.4 – SQL Injection
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
[*, 3.4)
3.4
29/07/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.