Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-07-10

CVE-2026-13010 - JoomSport – for Sports: Team & League, Football, Hockey & more Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The shortcode can be embedded in…

PLUGIN JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-13010

MEDIUM CVSS 6.5 2026-07-10
Threat Entry Updated 2026-07-02

CVE-2026-12134 - JoomSport – for Sports: Team & League, Football, Hockey & more Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode.

PLUGIN JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-12134

MEDIUM CVSS 4.3 2026-07-02
Threat Entry Updated 2026-07-01

CVE-2026-12133 - JoomSport – for Sports: Team & League, Football, Hockey & more Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport group records.

PLUGIN JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-12133

MEDIUM CVSS 4.3 2026-07-01
Scroll to top