Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-43340

Disclosure Date: October 19, 2023 (last updated October 28, 2023)
Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters
Attacker Value
Unknown

CVE-2023-43341

Disclosure Date: October 19, 2023 (last updated October 31, 2023)
Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter.
Attacker Value
Unknown

CVE-2022-44036

Disclosure Date: January 03, 2023 (last updated November 08, 2023)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Attacker Value
Unknown

CVE-2021-31632

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
Attacker Value
Unknown

CVE-2021-31631

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Attacker Value
Unknown

CVE-2020-23238

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
Attacker Value
Unknown

CVE-2020-22839

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
Attacker Value
Unknown

CVE-2019-14518

Disclosure Date: August 15, 2019 (last updated November 08, 2023)
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
0
Attacker Value
Unknown

CVE-2018-16637

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
0
Attacker Value
Unknown

CVE-2018-16638

Disclosure Date: December 28, 2018 (last updated November 27, 2024)
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
0