Vulnerabilities (CVE)

Filtered by vendor B2evolution Subscribe
Filtered by product B2evolution
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28242 1 B2evolution 1 B2evolution 2022-05-03 6.5 MEDIUM 8.8 HIGH
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
CVE-2016-9479 1 B2evolution 1 B2evolution 2017-07-28 5.0 MEDIUM 7.5 HIGH
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
CVE-2017-5480 1 B2evolution 1 B2evolution 2017-01-18 5.5 MEDIUM 8.1 HIGH
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.