Vulnerabilities (CVE)

Filtered by vendor B2evolution Subscribe
Filtered by product B2evolution
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28242 1 B2evolution 1 B2evolution 2024-11-21 6.5 MEDIUM 8.8 HIGH
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
CVE-2020-22841 1 B2evolution 1 B2evolution 2024-11-21 3.5 LOW 4.8 MEDIUM
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
CVE-2020-22840 1 B2evolution 1 B2evolution 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
CVE-2017-1000423 1 B2evolution 1 B2evolution 2024-11-21 7.5 HIGH 9.8 CRITICAL
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
CVE-2016-8901 1 B2evolution 1 B2evolution 2024-11-21 7.5 HIGH 9.8 CRITICAL
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.