Beardev maintains a narrowly focused product portfolio centered on Joomsport, a Joomla-based sports management extension that serves niche deployment contexts. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the recurring weakness classes—SQL injection, missing authorization, and untrusted deserialization—reflecting input-handling and access-control gaps typical of web application extensions. Defenders should prioritize patches for this vendor's disclosures and audit instances of Joomsport for exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beardev over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14348CRITICAL The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid par | Aug 5, 2019 | 9.8 | 52 | NO | YES |
CVE-2026-42647CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.
This issue affects JoomSport: f | Jun 11, 2026 | 9.3 | 47 | NO | YES |
CVE-2022-4050CRITICAL The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthen | Dec 19, 2022 | 9.8 | 44 | NO | YES |
CVE-2021-24384CRITICAL The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the sh | Jul 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2024-44031HIGH Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects JoomSport: from n/a through <= 5.6.3. | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-43355HIGH Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.3. | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-2718MEDIUM The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields | Sep 6, 2022 | 4.9 | 20 | NO | NO |
CVE-2022-2717MEDIUM The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page | Sep 6, 2022 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beardev.
Media articles that mention a CVE ID that affects a product developed by Beardev — matched by CVE ID, not by vendor name.