B2evolution
B2evolution CMS: vulnerabilities and CVEs
B2evolution CMS has 5 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76834 | Critical (9.2) | 0.85% | — | Sep 17, 2026 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array… |
| CVE-2022-44036 | High (7.2) | 1.1% | — | Jan 3, 2023 | In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a… |
| CVE-2021-31632 | Critical (9.8) | 1.9% | — | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input. |
| CVE-2021-31631 | High (8.8) | 0.55% | — | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges. |
| CVE-2020-22839 | Medium (6.1) | 4.5% | — | Feb 9, 2021 | Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.