JoomSport - SQLi (CVE-2026-42647)
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.
This issue affects JoomSport <= 5.7.7.
psychologyCrowdSec Analysis
CVE-2026-42647 is a critical SQL injection vulnerability in Beardev JoomSport versions up to 5.7.7, allowing attackers to perform blind SQL injection attacks. Exploiting this flaw could enable remote, unauthenticated attackers to extract sensitive data from the database or manipulate backend queries, posing a significant risk to data confidentiality and application integrity.
CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-42647 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers exploit the JoomSport plugin by sending crafted requests to player list endpoints with a malicious sortf parameter, such as /.../playerlist&sortf=post_title%60,(SELECT/**/x/**/FROM/**/(SELECT/**/SLEEP(6)/**/AS/**/x)/**/AS/**/t)%23, to trigger unauthenticated time-based blind SQL injection. This targets URLs containing action=playerlist and manipulates the sortf parameter to execute arbitrary SQL code.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-06-11 |
| Rule Released | 2026-07-01 |