CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-42647Public Exploit

JoomSport - SQLi (CVE-2026-42647)

PublishedJun 11, 2026
First SeenN/A
Last Seen
Reported
CVSS9.3
cms

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.

This issue affects JoomSport <= 5.7.7.

psychologyCrowdSec Analysis

CVE-2026-42647 is a critical SQL injection vulnerability in Beardev JoomSport versions up to 5.7.7, allowing attackers to perform blind SQL injection attacks. Exploiting this flaw could enable remote, unauthenticated attackers to extract sensitive data from the database or manipulate backend queries, posing a significant risk to data confidentiality and application integrity.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-42647 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers exploit the JoomSport plugin by sending crafted requests to player list endpoints with a malicious sortf parameter, such as /.../playerlist&sortf=post_title%60,(SELECT/**/x/**/FROM/**/(SELECT/**/SLEEP(6)/**/AS/**/x)/**/AS/**/t)%23, to trigger unauthenticated time-based blind SQL injection. This targets URLs containing action=playerlist and manipulates the sortf parameter to execute arbitrary SQL code.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-06-11
Rule Released2026-07-01

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.