Bitrix24 is a narrowly scoped collaboration and business-management platform whose vulnerability profile punches above its modest product footprint, with disclosures affecting core components including the main Bitrix24 offering, Site Manager, and the underlying framework. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, reflecting the platform's web-facing nature and the appeal of its widely deployed enterprise instances to attackers seeking compromise and lateral movement. The exposure recurs across input-handling, authentication, and file-handling boundaries through weakness classes including cross-site scripting, insufficiently protected credentials, unrestricted file uploads, cleartext sensitive-data storage, and untrusted deserialization—patterns characteristic of web-application stacks where user input flows directly into templating and serialization logic. Defenders should treat Bitrix24 advisories as high-priority, particularly for internet-exposed instances and administrative interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitrix24 over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27228CRITICAL In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | Mar 22, 2022 | 9.8 | 53 | NO | YES |
CVE-2023-1719CRITICAL Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute | Nov 1, 2023 | 9.8 | 41 | NO | YES |
CVE-2023-1718HIGH
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted " | Nov 1, 2023 | 7.5 | 33 | NO | NO |
CVE-2023-1717CRITICAL
Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code i | Nov 1, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-1716CRITICAL
Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly exec | Nov 1, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-1713HIGH Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to exe | Nov 1, 2023 | 8.8 | 26 | NO | NO |
CVE-2020-13483MEDIUM The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI. | Jun 24, 2020 | 6.1 | 26 | NO | YES |
CVE-2023-1720HIGH Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbi | Nov 1, 2023 | 8.0 | 25 | NO | NO |
CVE-2023-1714HIGH Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appe | Nov 1, 2023 | 8.8 | 25 | NO | NO |
CVE-2008-2052MEDIUM Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th | May 2, 2008 | 6.1 | 25 | NO | YES |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitrix24.
Media articles that mention a CVE ID that affects a product developed by Bitrix24 — matched by CVE ID, not by vendor name.