B2evolution

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 30
    Known Exploited: 0
    5
    Critical Level Threats
    9
    High Level Threats
    16
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47800

    b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)

    Last Modified: Apr 15, 2026
    Published: Jan 15, 2026

    CVE-2022-44036

    In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."

    Last Modified: Nov 21, 2024
    Published: Jan 03, 2023

    CVE-2022-30935

    An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

    Last Modified: May 21, 2025
    Published: Sep 28, 2022

    CVE-2021-31632

    b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

    Last Modified: Nov 21, 2024
    Published: Dec 06, 2021

    CVE-2021-31631

    b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.

    Last Modified: Nov 21, 2024
    Published: Dec 06, 2021
    Items Per Page
    B2evolution Vulnerabilities & Security CVEs | CVE-DB