Back to Database
Status published
Medium
CVE-2020-22841
Stored XSS in b2evolution CMS version 6.11.6 and prior allows...
Vulnerability Description
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-22841
Credits & Attribution
No credits recorded in the NVD database.
References
More from b2evolution
View All →CVE-2022-44036
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload...
Unknown
0
CVE-2022-30935
An authorization bypass in b2evolution allows remote, unauthenticated attackers to...
Unknown
0
CVE-2021-31632
b2evolution CMS v7.2.3 was discovered to contain a SQL injection...
Critical
9.8
CVE-2021-31631
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request...
High
8.8
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows...
High
8.8
Affected Vendor
b2evolution
View all reports →Affected Software
b2evolution
Vulnerable Versions:
0
Timeline
Official Publish:
February 9th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.