JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
medium
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...
- CVSS:
- 4.9
- Affected:
- up to 5.7.9
- Fixed in:
- 5.7.10
- Disclosed:
- Aug 4, 2026
CVE-2026-11920 on NVD →
JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute
medium
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- CVSS:
- 6.5
- Affected:
- up to 5.7.9
- Fixed in:
- 5.7.10
- Disclosed:
- Jul 9, 2026
CVE-2026-13010 on NVD →
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
medium
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,...
- CVSS:
- 4.3
- Affected:
- up to 5.7.8
- Fixed in:
- 5.7.9
- Disclosed:
- Jul 1, 2026
CVE-2026-12134 on NVD →
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
medium
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce befor...
- CVSS:
- 4.3
- Affected:
- up to 5.7.8
- Fixed in:
- 5.7.9
- Disclosed:
- Jun 30, 2026
CVE-2026-12133 on NVD →
JoomSport <= 5.7.7 - Unauthenticated SQL Injection via 'sortf' Parameter
high
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- CVSS:
- 7.5
- Affected:
- up to 5.7.7
- Fixed in:
- 5.7.8
- Disclosed:
- May 12, 2026
CVE-2026-6929 on NVD →
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 - Unauthenticated SQL Injection
high
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica...
- CVSS:
- 7.5
- Affected:
- up to 5.7.7
- Fixed in:
- 5.7.8
- Disclosed:
- Apr 29, 2026
CVE-2026-42647 on NVD →
JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion
critical
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the e...
- CVSS:
- 9.8
- Affected:
- up to 5.7.3
- Fixed in:
- 5.7.4
- Disclosed:
- Oct 2, 2025
CVE-2025-7721 on NVD →
JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page
high
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.1
- Affected:
- up to 5.6.17
- Fixed in:
- 5.6.18
- Disclosed:
- Jan 6, 2025
CVE-2024-12633 on NVD →
JoomSport <= 5.6.3 - Missing Authorization
medium
The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_create_tlslider() function in versions up to, and including, 5.6.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to create sliders.
- CVSS:
- 4.3
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Sep 24, 2024
CVE-2024-44031 on NVD →
JoomSport <= 5.3.0 - Missing Authorization
medium
The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the joomsport_update_option and joomsport_senddeactivation functions in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 5.3.0
- Fixed in:
- 5.5.7
- Disclosed:
- Aug 16, 2024
CVE-2024-43355 on NVD →
JoomSport <= 5.2.7 - Unauthenticated SQL Injection
critical
The JoomSport plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...
- CVSS:
- 9.8
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Nov 28, 2022
CVE-2022-4050 on NVD →
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby
high
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
- CVSS:
- 7.2
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Aug 8, 2022
CVE-2022-2717 on NVD →
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby
high
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- CVSS:
- 7.2
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Aug 8, 2022
CVE-2022-2718 on NVD →
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 - Object Injection
critical
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this,...
- CVSS:
- 9.8
- Affected:
- up to 5.1.8
- Fixed in:
- 5.1.8
- Disclosed:
- Jun 8, 2021
CVE-2021-24384 on NVD →
JoomSport – for Sports: Team & League, Football, Hockey & more < 3.4 - SQL Injection
critical
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
- CVSS:
- 9.8
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- Jul 29, 2019
CVE-2019-14348 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database