plugin

Joomsport Sports League Results Management Vulnerabilities

15 known security issues reported for the Joomsport Sports League Results Management WordPress plugin. Most recent disclosed Aug 4, 2026.

4 critical 5 high 6 medium

Running Joomsport Sports League Results Management on your site? Check whether your installed version is affected.

Scan your site free

JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter

medium

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...

CVSS:
4.9
Affected:
up to 5.7.9
Fixed in:
5.7.10
Disclosed:
Aug 4, 2026

CVE-2026-11920 on NVD →

JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute

medium

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

CVSS:
6.5
Affected:
up to 5.7.9
Fixed in:
5.7.10
Disclosed:
Jul 9, 2026

CVE-2026-13010 on NVD →

JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action

medium

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,...

CVSS:
4.3
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Jul 1, 2026

CVE-2026-12134 on NVD →

JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action

medium

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce befor...

CVSS:
4.3
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Jun 30, 2026

CVE-2026-12133 on NVD →

JoomSport <= 5.7.7 - Unauthenticated SQL Injection via 'sortf' Parameter

high

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

CVSS:
7.5
Affected:
up to 5.7.7
Fixed in:
5.7.8
Disclosed:
May 12, 2026

CVE-2026-6929 on NVD →

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 - Unauthenticated SQL Injection

high

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica...

CVSS:
7.5
Affected:
up to 5.7.7
Fixed in:
5.7.8
Disclosed:
Apr 29, 2026

CVE-2026-42647 on NVD →

JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion

critical

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the e...

CVSS:
9.8
Affected:
up to 5.7.3
Fixed in:
5.7.4
Disclosed:
Oct 2, 2025

CVE-2025-7721 on NVD →

JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page

high

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
7.1
Affected:
up to 5.6.17
Fixed in:
5.6.18
Disclosed:
Jan 6, 2025

CVE-2024-12633 on NVD →

JoomSport <= 5.6.3 - Missing Authorization

medium

The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_create_tlslider() function in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to create sliders.

CVSS:
4.3
Affected:
up to 5.6.3
Fixed in:
5.6.4
Disclosed:
Sep 24, 2024

CVE-2024-44031 on NVD →

JoomSport <= 5.3.0 - Missing Authorization

medium

The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_update_option and joomsport_senddeactivation functions in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
4.3
Affected:
up to 5.3.0
Fixed in:
5.5.7
Disclosed:
Aug 16, 2024

CVE-2024-43355 on NVD →

JoomSport <= 5.2.7 - Unauthenticated SQL Injection

critical

The JoomSport plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...

CVSS:
9.8
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Nov 28, 2022

CVE-2022-4050 on NVD →

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby

high

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

CVSS:
7.2
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Aug 8, 2022

CVE-2022-2717 on NVD →

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby

high

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

CVSS:
7.2
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Aug 8, 2022

CVE-2022-2718 on NVD →

JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 - Object Injection

critical

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this,...

CVSS:
9.8
Affected:
up to 5.1.8
Fixed in:
5.1.8
Disclosed:
Jun 8, 2021

CVE-2021-24384 on NVD →

JoomSport – for Sports: Team & League, Football, Hockey & more < 3.4 - SQL Injection

critical

The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

CVSS:
9.8
Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
Jul 29, 2019

CVE-2019-14348 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database