B2evolution is a modestly represented blogging and content-management platform whose vulnerability footprint reflects the challenges of web-application input handling and access control. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code, concentrating in the core B2evolution CMS and its StarRating plugin. The exposure recurs durably through web-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and path traversal, reflecting the attack surface inherent to user-facing, database-driven content platforms. Defenders should prioritize updates to internet-exposed instances and monitor third-party plugin integrations for similar input-validation gaps. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by B2evolution over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28242HIGH SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_nam | Apr 15, 2021 | 8.8 | 39 | NO | YES |
CVE-2016-8901CRITICAL b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. | May 23, 2019 | 9.8 | 33 | NO | NO |
CVE-2017-1000423CRITICAL b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gainin | Jan 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-22840MEDIUM Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to par | Feb 9, 2021 | 6.1 | 31 | NO | YES |
CVE-2021-31632CRITICAL b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to exec | Dec 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2017-5539CRITICAL The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this att | Jan 23, 2017 | 9.1 | 30 | NO | NO |
CVE-2022-30935CRITICAL An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This all | Sep 28, 2022 | 9.1 | 29 | NO | NO |
CVE-2006-6417HIGH PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in | Dec 10, 2006 | 7.5 | 29 | NO | YES |
CVE-2017-5480HIGH Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-of | Jan 15, 2017 | 8.1 | 28 | NO | NO |
CVE-2021-31631HIGH b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges. | Dec 6, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by B2evolution.
Media articles that mention a CVE ID that affects a product developed by B2evolution — matched by CVE ID, not by vendor name.