CVE-2022-4050
- EPSS 4.76%
- Veröffentlicht 19.12.2022 14:15:11
- Zuletzt bearbeitet 17.04.2025 14:15:24
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
CVE-2022-2717
- EPSS 1.2%
- Veröffentlicht 06.09.2022 18:15:14
- Zuletzt bearbeitet 08.04.2026 18:17:26
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping ...
CVE-2022-2718
- EPSS 1.2%
- Veröffentlicht 06.09.2022 18:15:14
- Zuletzt bearbeitet 08.04.2026 18:17:26
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient esca...
CVE-2021-24384
- EPSS 2.07%
- Veröffentlicht 06.07.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:57
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even tho...
CVE-2019-14348
- EPSS 20.51%
- Veröffentlicht 05.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:33
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.