Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bitrix24

First CVE: May 2, 2008Active for: 18 yearsTotal CVEs: 20
36.5
VTI Score
Medium

Bitrix24 is a narrowly scoped collaboration and business-management platform whose vulnerability profile punches above its modest product footprint, with disclosures affecting core components including the main Bitrix24 offering, Site Manager, and the underlying framework. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, reflecting the platform's web-facing nature and the appeal of its widely deployed enterprise instances to attackers seeking compromise and lateral movement. The exposure recurs across input-handling, authentication, and file-handling boundaries through weakness classes including cross-site scripting, insufficiently protected credentials, unrestricted file uploads, cleartext sensitive-data storage, and untrusted deserialization—patterns characteristic of web-application stacks where user input flows directly into templating and serialization logic. Defenders should treat Bitrix24 advisories as high-priority, particularly for internet-exposed instances and administrative interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bitrix24 over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2008
18 years ago
Most Recent CVE
Nov 4, 2024
627 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-27228CRITICAL
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
Mar 22, 20229.853NOYES
CVE-2023-1719CRITICAL
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute
Nov 1, 20239.841NOYES
CVE-2023-1718HIGH
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "
Nov 1, 20237.533NONO
CVE-2023-1717CRITICAL
Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code i
Nov 1, 20239.630NONO
CVE-2023-1716CRITICAL
Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly exec
Nov 1, 20239.630NONO
CVE-2023-1713HIGH
Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to exe
Nov 1, 20238.826NONO
CVE-2020-13483MEDIUM
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
Jun 24, 20206.126NOYES
CVE-2023-1720HIGH
Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbi
Nov 1, 20238.025NONO
CVE-2023-1714HIGH
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appe
Nov 1, 20238.825NONO
CVE-2008-2052MEDIUM
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th
May 2, 20086.125NOYES
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
55%
20%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (65.0%)
Unknown0 (0.0%)
Required7 (35.0%)
Privileges Required
Low6 (30.0%)
High6 (30.0%)
None8 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bitrix24.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bitrix24 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bitrix24's Products

View all 3 CNAs →

Top CWEs