b2evolution CVE Vulnerabilities & Metrics

Focus on b2evolution vulnerabilities and metrics.

Last updated: 16 Apr 2025, 22:25 UTC

About b2evolution Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with b2evolution. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total b2evolution CVEs: 18
Earliest CVE date: 01 Dec 2006, 01:28 UTC
Latest CVE date: 03 Jan 2023, 21:15 UTC

Latest CVE reference: CVE-2022-44036

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical b2evolution CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.46

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 15
7.0-8.9 7
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS b2evolution CVEs

These are the five CVEs with the highest CVSS scores for b2evolution, sorted by severity first and recency.

All CVEs for b2evolution

CVE-2022-44036 b2evolution vulnerability CVSS: 0 03 Jan 2023, 21:15 UTC

In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."

CVE-2022-30935 b2evolution vulnerability CVSS: 0 28 Sep 2022, 11:15 UTC

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

CVE-2021-31632 b2evolution vulnerability CVSS: 7.5 06 Dec 2021, 22:15 UTC

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

CVE-2021-31631 b2evolution vulnerability CVSS: 6.8 06 Dec 2021, 22:15 UTC

b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.

CVE-2021-28242 b2evolution vulnerability CVSS: 6.5 15 Apr 2021, 14:15 UTC

SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

CVE-2020-22839 b2evolution vulnerability CVSS: 4.3 09 Feb 2021, 20:15 UTC

Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.

CVE-2020-22841 b2evolution vulnerability CVSS: 3.5 09 Feb 2021, 14:15 UTC

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

CVE-2020-22840 b2evolution vulnerability CVSS: 5.8 09 Feb 2021, 14:15 UTC

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

CVE-2016-8901 b2evolution vulnerability CVSS: 7.5 23 May 2019, 18:29 UTC

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

CVE-2017-1000423 b2evolution vulnerability CVSS: 7.5 02 Jan 2018, 20:29 UTC

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.

CVE-2017-5553 b2evolution vulnerability CVSS: 3.5 23 Jan 2017, 07:59 UTC

Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.

CVE-2017-5539 b2evolution vulnerability CVSS: 9.0 23 Jan 2017, 07:59 UTC

The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit this vulnerability to delete or read any files on the server. It can also be used to determine whether a file exists.

CVE-2016-7150 b2evolution vulnerability CVSS: 3.5 18 Jan 2017, 17:59 UTC

Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.

CVE-2016-7149 b2evolution vulnerability CVSS: 4.3 18 Jan 2017, 17:59 UTC

Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function.

CVE-2017-5494 b2evolution vulnerability CVSS: 3.5 15 Jan 2017, 22:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.

CVE-2017-5480 b2evolution vulnerability CVSS: 5.5 15 Jan 2017, 22:59 UTC

Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.

CVE-2016-9479 b2evolution vulnerability CVSS: 5.0 02 Dec 2016, 16:59 UTC

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

CVE-2014-9599 b2evolution vulnerability CVSS: 4.3 16 Jan 2015, 15:59 UTC

Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to inject arbitrary web script or HTML via the fm_filter parameter to blogs/admin.php.

CVE-2013-7352 b2evolution vulnerability CVSS: 6.8 02 Apr 2014, 18:55 UTC

Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.

CVE-2013-2945 b2evolution vulnerability CVSS: 6.5 02 Apr 2014, 16:17 UTC

SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

CVE-2012-5911 b2evolution vulnerability CVSS: 4.3 17 Nov 2012, 21:55 UTC

Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

CVE-2012-5910 b2evolution vulnerability CVSS: 6.5 17 Nov 2012, 21:55 UTC

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

CVE-2011-3709 b2evolution vulnerability CVSS: 5.0 23 Sep 2011, 23:55 UTC

b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain other files.

CVE-2009-1657 b2evolution vulnerability CVSS: 7.5 18 May 2009, 12:00 UTC

Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2007-2681 b2evolution vulnerability CVSS: 7.5 15 May 2007, 00:19 UTC

Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter.

CVE-2007-2358 b2evolution vulnerability CVSS: 7.5 30 Apr 2007, 22:19 UTC

Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php. NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used

CVE-2007-0175 b2evolution vulnerability CVSS: 4.3 11 Jan 2007, 00:28 UTC

Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.

CVE-2006-6417 b2evolution vulnerability CVSS: 7.5 10 Dec 2006, 11:28 UTC

PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

CVE-2006-6197 b2evolution vulnerability CVSS: 6.8 01 Dec 2006, 01:28 UTC

Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.