CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-76834 CRITICAL

b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key

CVSS 9.2 EPSS 0.85% Sep 17, 2026
CVE-2021-47800 MEDIUM

b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)

CVSS 6.9 EPSS 0.17% Jan 15, 2026
CVE-2022-44036 HIGH

In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE…

CVSS 7.2 EPSS 1.11% Jan 3, 2023
CVE-2022-30935 CRITICAL

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomne…

CVSS 9.1 EPSS 1.40% Sep 28, 2022
CVE-2021-31632 CRITICAL

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability all…

CVSS 9.8 EPSS 1.87% Dec 6, 2021
CVE-2021-31631 HIGH

b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate p…

CVSS 8.8 EPSS 0.55% Dec 6, 2021
CVE-2021-28242 HIGH

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL comm…

CVSS 8.8 EPSS 4.96% Apr 15, 2021
CVE-2020-22839 MEDIUM

Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary…

CVSS 6.1 EPSS 4.50% Feb 9, 2021
CVE-2020-22841 MEDIUM

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the…

CVSS 4.8 EPSS 3.54% Feb 9, 2021
CVE-2020-22840 MEDIUM

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resourc…

CVSS 6.1 EPSS 13.82% Feb 9, 2021
CVE-2016-8901 CRITICAL

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

CVSS 9.8 EPSS 2.42% May 23, 2019
CVE-2017-1000423 CRITICAL

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenti…

CVSS 9.8 EPSS 2.39% Jan 2, 2018
CVE-2017-5553 MEDIUM

Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to injec…

CVSS 5.4 EPSS 1.20% Jan 23, 2017
CVE-2017-5539 CRITICAL

The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter…

CVSS 9.1 EPSS 4.17% Jan 23, 2017
CVE-2016-7150 MEDIUM

Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site…

CVSS 5.4 EPSS 0.90% Jan 18, 2017
CVE-2016-7149 MEDIUM

Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to…

CVSS 6.1 EPSS 1.24% Jan 18, 2017
CVE-2017-5494 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary w…

CVSS 5.4 EPSS 1.18% Jan 15, 2017
CVE-2017-5480 HIGH

Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files…

CVSS 8.1 EPSS 2.46% Jan 15, 2017
CVE-2016-9479 HIGH

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

CVSS 7.5 EPSS 1.84% Dec 2, 2016
CVE-2014-9599 MEDIUM

Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 EPSS 2.21% Jan 16, 2015
CVE-2013-7352 MEDIUM

Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administ…

CVSS 6.8 EPSS 0.61% Apr 2, 2014
CVE-2013-2945 MEDIUM

SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the…

CVSS 6.5 EPSS 2.77% Apr 2, 2014
CVE-2012-5911 MEDIUM

Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message…

CVSS 4.3 EPSS 1.33% Nov 17, 2012
CVE-2012-5910 MEDIUM

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root p…

CVSS 6.5 EPSS 1.15% Nov 17, 2012
CVE-2011-3709 MEDIUM

b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error…

CVSS 5.0 EPSS 1.34% Sep 23, 2011

Showing 1 to 25 CVEs · page 1 (more available)