B2Evolution records
29 published records for vendor b2evolution.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 3.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-330 Use of Insufficiently Random Values1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-8901No exploit | b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.b2evolution · b2evolution · CWE-74 | Critical9.8 | — | 2.4% | May 23, 2019 |
40Plan | CVE-2017-1000423No exploit | b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resub2evolution · b2evolution · CWE-20 | Critical9.8 | — | 2.4% | Jan 2, 2018 |
40Plan | CVE-2021-31632No exploit | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section.b2evolution · b2evolution cms · CWE-89 | Critical9.8 | — | 1.9% | Dec 6, 2021 |
37Monitor | CVE-2017-5539No exploit | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability.b2evolution · b2evolution · CWE-22 | Critical9.1 | — | 4.2% | Jan 23, 2017 |
36Monitor | CVE-2021-28242Proof of concept | SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information byb2evolution · b2evolution · CWE-89 | High8.8 | — | 5.0% | Apr 15, 2021 |
36Monitor | CVE-2022-30935No exploit | An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the usb2evolution · b2evolution · CWE-330 | Critical9.1 | — | 1.4% | Sep 28, 2022 |
35Monitor | CVE-2021-31631No exploit | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page.b2evolution · b2evolution cms · CWE-352 | High8.8 | — | 0.6% | Dec 6, 2021 |
33Monitor | CVE-2017-5480No exploit | Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or deleb2evolution · b2evolution · CWE-22 | High8.1 | — | 2.5% | Jan 15, 2017 |
31Monitor | CVE-2006-6417Proof of concept | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers tob2evolution · b2evolution | High7.5 | — | 3.4% | Dec 10, 2006 |
31Monitor | CVE-2007-2358No exploit | Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) b2evolution · b2evolution | High7.5 | — | 2.5% | Apr 30, 2007 |
31Monitor | CVE-2016-9479No exploit | The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted requesb2evolution · b2evolution · CWE-255 | High7.5 | — | 1.8% | Dec 2, 2016 |
30Monitor | CVE-2007-2681No exploit | Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local filesb2evolution · b2evolution | High7.5 | — | 1.5% | May 14, 2007 |
30Monitor | CVE-2009-1657No exploit | Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQLb2evolution · b2evolution · CWE-89 | High7.5 | — | 1.1% | May 18, 2009 |
28Monitor | CVE-2020-22840Proof of concept | Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attackerb2evolution · b2evolution · CWE-601 | Medium6.1 | — | 13.8% | Feb 9, 2021 |
28Monitor | CVE-2006-6197Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web scrb2evolution · b2evolution | Medium6.8 | — | 1.9% | Nov 30, 2006 |
28Monitor | CVE-2022-44036No exploit | In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to commb2evolution · b2evolution cms · CWE-434 | High7.2 | — | 1.1% | Jan 3, 2023 |
27Monitor | CVE-2013-2945Proof of concept | SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary Sb2evolution · b2evolution · CWE-89 | Medium6.5 | — | 2.8% | Apr 2, 2014 |
27Monitor | CVE-2013-7352No exploit | Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentb2evolution · b2evolution · CWE-352 | Medium6.8 | — | 0.6% | Apr 2, 2014 |
26Monitor | CVE-2012-5910No exploit | SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commb2evolution · b2evolution · CWE-89 | Medium6.5 | — | 1.2% | Nov 17, 2012 |
25Monitor | CVE-2020-22839No exploit | Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers tb2evolution · b2evolution cms · CWE-79 | Medium6.1 | — | 4.5% | Feb 9, 2021 |
24Monitor | CVE-2016-7149No exploit | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML viab2evolution · b2evolution · CWE-79 | Medium6.1 | — | 1.2% | Jan 18, 2017 |
21Monitor | CVE-2017-5553No exploit | Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticb2evolution · b2evolution · CWE-79 | Medium5.4 | — | 1.2% | Jan 23, 2017 |
21Monitor | CVE-2017-5494No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users tob2evolution · b2evolution · CWE-79 | Medium5.4 | — | 1.2% | Jan 15, 2017 |
21Monitor | CVE-2016-7150No exploit | Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script ob2evolution · b2evolution · CWE-79 | Medium5.4 | — | 0.9% | Jan 18, 2017 |
20Monitor | CVE-2020-22841Proof of concept | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin nameb2evolution · b2evolution · CWE-79 | Medium4.8 | — | 3.5% | Feb 9, 2021 |
- CVE-2016-890140Plan
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
CriticalCVSS 9.8No exploitEPSS 2%b2evolution · b2evolutionMay 23, 2019
- CVE-2017-100042340Plan
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resu
CriticalCVSS 9.8No exploitEPSS 2%b2evolution · b2evolutionJan 2, 2018
- CVE-2021-3163240Plan
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section.
CriticalCVSS 9.8No exploitEPSS 2%b2evolution · b2evolution cmsDec 6, 2021
- CVE-2017-553937Monitor
The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability.
CriticalCVSS 9.1No exploitEPSS 4%b2evolution · b2evolutionJan 23, 2017
- CVE-2021-2824236Monitor
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by
HighCVSS 8.8Proof of conceptEPSS 5%b2evolution · b2evolutionApr 15, 2021
- CVE-2022-3093536Monitor
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the us
CriticalCVSS 9.1No exploitEPSS 1%b2evolution · b2evolutionSep 28, 2022
- CVE-2021-3163135Monitor
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page.
HighCVSS 8.8No exploitEPSS 1%b2evolution · b2evolution cmsDec 6, 2021
- CVE-2017-548033Monitor
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or dele
HighCVSS 8.1No exploitEPSS 2%b2evolution · b2evolutionJan 15, 2017
- CVE-2006-641731Monitor
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 3%b2evolution · b2evolutionDec 10, 2006
- CVE-2007-235831Monitor
Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1)
HighCVSS 7.5No exploitEPSS 2%b2evolution · b2evolutionApr 30, 2007
- CVE-2016-947931Monitor
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted reques
HighCVSS 7.5No exploitEPSS 2%b2evolution · b2evolutionDec 2, 2016
- CVE-2007-268130Monitor
Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files
HighCVSS 7.5No exploitEPSS 1%b2evolution · b2evolutionMay 14, 2007
- CVE-2009-165730Monitor
Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL
HighCVSS 7.5No exploitEPSS 1%b2evolution · b2evolutionMay 18, 2009
- CVE-2020-2284028Monitor
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker
MediumCVSS 6.1Proof of conceptEPSS 14%b2evolution · b2evolutionFeb 9, 2021
- CVE-2006-619728Monitor
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web scr
MediumCVSS 6.8Proof of conceptEPSS 2%b2evolution · b2evolutionNov 30, 2006
- CVE-2022-4403628Monitor
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to comm
HighCVSS 7.2No exploitEPSS 1%b2evolution · b2evolution cmsJan 3, 2023
- CVE-2013-294527Monitor
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary S
MediumCVSS 6.5Proof of conceptEPSS 3%b2evolution · b2evolutionApr 2, 2014
- CVE-2013-735227Monitor
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authent
MediumCVSS 6.8No exploitEPSS 1%b2evolution · b2evolutionApr 2, 2014
- CVE-2012-591026Monitor
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL comm
MediumCVSS 6.5No exploitEPSS 1%b2evolution · b2evolutionNov 17, 2012
- CVE-2020-2283925Monitor
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers t
MediumCVSS 6.1No exploitEPSS 4%b2evolution · b2evolution cmsFeb 9, 2021
- CVE-2016-714924Monitor
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 6.1No exploitEPSS 1%b2evolution · b2evolutionJan 18, 2017
- CVE-2017-555321Monitor
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authentic
MediumCVSS 5.4No exploitEPSS 1%b2evolution · b2evolutionJan 23, 2017
- CVE-2017-549421Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to
MediumCVSS 5.4No exploitEPSS 1%b2evolution · b2evolutionJan 15, 2017
- CVE-2016-715021Monitor
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script o
MediumCVSS 5.4No exploitEPSS 1%b2evolution · b2evolutionJan 18, 2017
- CVE-2020-2284120Monitor
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name
MediumCVSS 4.8Proof of conceptEPSS 4%b2evolution · b2evolutionFeb 9, 2021