Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

B2evolution

First CVE: Dec 1, 2006Active for: 20 yearsTotal CVEs: 29
44.3
VTI Score
High

B2evolution is a modestly represented blogging and content-management platform whose vulnerability footprint reflects the challenges of web-application input handling and access control. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code, concentrating in the core B2evolution CMS and its StarRating plugin. The exposure recurs durably through web-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and path traversal, reflecting the attack surface inherent to user-facing, database-driven content platforms. Defenders should prioritize updates to internet-exposed instances and monitor third-party plugin integrations for similar input-validation gaps. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by B2evolution over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2006
19 years ago
Most Recent CVE
Jan 3, 2023
1,299 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-28242HIGH
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_nam
Apr 15, 20218.839NOYES
CVE-2016-8901CRITICAL
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
May 23, 20199.833NONO
CVE-2017-1000423CRITICAL
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gainin
Jan 2, 20189.832NONO
CVE-2020-22840MEDIUM
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to par
Feb 9, 20216.131NOYES
CVE-2021-31632CRITICAL
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to exec
Dec 6, 20219.830NONO
CVE-2017-5539CRITICAL
The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this att
Jan 23, 20179.130NONO
CVE-2022-30935CRITICAL
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This all
Sep 28, 20229.129NONO
CVE-2006-6417HIGH
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in
Dec 10, 20067.529NOYES
CVE-2017-5480HIGH
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-of
Jan 15, 20178.128NONO
CVE-2021-31631HIGH
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Dec 6, 20218.827NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
52%
31%
17%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (58.6%)
Unknown12 (41.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (58.6%)
High0 (0.0%)
Unknown12 (41.4%)
User Interaction
None9 (31.0%)
Unknown12 (41.4%)
Required8 (27.6%)
Privileges Required
Low5 (17.2%)
High2 (6.9%)
None10 (34.5%)
Unknown12 (41.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.4% of CVEs· 95th percentile
ExploitDB
5 CVEs
17.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by B2evolution.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by B2evolution — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For B2evolution's Products

View all 1 CNAs →

Top CWEs