All 4 CVE vulnerabilities found in SportsPress – Sports Club & League Manager, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-15368 | SportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode CWE-98 | 8.8 | High | 2026-02-04 |
| CVE-2024-34824 | WordPress SportsPress – Sports Club & League Manager plugin <= 2.7.20 - Broken Access Control vulnerability CWE-862 | 4.3 | Medium | 2024-06-11 |
| CVE-2024-1178 | SportsPress – Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update CWE-862 | 5.3 | Medium | 2024-03-05 |
| CVE-2021-24578 | SportsPress < 2.7.9 - Reflected Cross-Site Scripting CWE-79 | 6.1 | - | 2021-12-21 |
All 4 known CVE vulnerabilities affecting SportsPress – Sports Club & League Manager with full Chinese analysis, references, and POCs where available.