« Back to list

B2evolution

B2evolution CMS: vulnerabilities and CVEs

B2evolution CMS has 5 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months1
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76834Critical (9.2)0.85%—Sep 17, 2026
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array…
CVE-2022-44036High (7.2)1.1%—Jan 3, 2023
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a…
CVE-2021-31632Critical (9.8)1.9%—Dec 6, 2021
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
CVE-2021-31631High (8.8)0.55%—Dec 6, 2021
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
CVE-2020-22839Medium (6.1)4.5%—Feb 9, 2021
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by B2evolution