Extension WordPress
Vulnérabilités SportsPress – Sports Club & League Manager
Cette page rassemble les failles publiées pour SportsPress – Sports Club & League Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SportsPress – Sports Club & League Manager
6 fiches
SportsPress <= 2.7.26 – Authenticated (Contributor+) Local File Inclusion via Shortcode
The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and…
*-2.7.26
2.7.27
03/02/2026
SportsPress – Sports Club & League Manager <= 2.7.21 – Authenticated (Admin+) Stored Cross-Site Scripting
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.21 due to insufficient input sanitization and output escaping. This makes…
*-2.7.21
2.7.22
09/07/2024
SportsPress – Sports Club & League Manager <= 2.7.20 – Missing Authorization to Notice Dismissal
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_notices() function in versions up to, and including, 2.7.20. This makes it…
*-2.7.20
2.7.21
09/05/2024
SportsPress – Sports Club & League Manager <= 2.7.17 – Missing Authorization to Unauthenticated Event Permalink Update
The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes…
*-2.7.17
2.7.18
04/03/2024
SportsPress <= 2.7.8 – Reflected Cross-Site Scripting
The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
*-2.7.8
2.7.9
16/11/2021
SportsPress <= 2.7.1 – Cross-Site Scripting
The SportsPress plugin before 2.7.2 for WordPress allows XSS.
[*, 2.7.2)
2.7.2
07/06/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.