CVE-2020-22840: b2evolution

Medium severity, CVSS 6.1. EPSS: 13.8% chance of exploitation in the next 30 days.

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

Affected products

  • b2evolution b2evolution: before 6.11.6 (fixed in 6.11.6)

Published 2021-02-09. Last modified 2026-06-17.