Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

beardev — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting beardev. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Beardev is a software development tool primarily used for building and managing web applications. Historically, it has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues across its CVE history. The application's complex architecture and extensive plugin ecosystem have contributed to recurring security weaknesses, particularly in input validation and access control mechanisms. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests potential risks in production environments requiring strict hardening and regular updates.

CVE ID Title CVSS Severity Published
CVE-2026-11920 JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-89 4.9 Medium 2026-08-05
CVE-2026-13010 JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-89 6.5 Medium 2026-07-10
CVE-2026-12134 JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-862 4.3 Medium 2026-07-02
CVE-2026-12133 JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-862 4.3 Medium 2026-07-01
CVE-2026-42647 WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability — JoomSport CWE-89 9.3 Critical 2026-06-11
CVE-2026-6929 JoomSport <= 5.7.7 - Unauthenticated SQL Injection via 'sortf' Parameter — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-89 7.5 High 2026-05-13
CVE-2025-7721 JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-98 9.8 Critical 2025-10-03
CVE-2024-12633 JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-79 7.1 High 2025-01-07
CVE-2024-43355 WordPress JoomSport plugin <= 5.3.0 - Broken Access Control vulnerability — JoomSport CWE-862 4.3 Medium 2024-11-01
CVE-2024-44031 WordPress JoomSport plugin <= 5.6.3 - Broken Access Control vulnerability — JoomSport CWE-862 4.3 Medium 2024-11-01
CVE-2022-2718 JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-89 7.2 High 2022-09-06
CVE-2022-2717 JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby — JoomSport – for Sports: Team & League, Football, Hockey & more CWE-89 7.2 High 2022-09-06

This page lists every published CVE security advisory associated with beardev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.