VendorsBeardevjoomsportall versions
Vulnerabilities

Beardev Joomsport 1.0 WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-14348
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
Published 2019-08-05 · Modified
9.81 PoCEPSS 0.205
CVE-2022-4050
JoomSport < 5.2.8 - Unauthenticated SQLi
Published 2022-12-19 · Modified
9.8EPSS 0.048
CVE-2021-24384
JoomSport < 5.1.8 - Unauthenticated PHP Object Injection
Published 2021-07-06 · Modified
9.8EPSS 0.021
CVE-2024-43355
WordPress JoomSport plugin <= 5.3.0 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
8.8EPSS 0.004
CVE-2024-44031
WordPress JoomSport plugin <= 5.6.3 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
8.8EPSS 0.004
CVE-2022-2717
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby
Published 2022-09-06 · Modified
7.2EPSS 0.015
CVE-2022-2718
JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby
Published 2022-09-06 · Modified
7.2EPSS 0.015