CVE-2020-22841: b2evolution
Medium severity, CVSS 4.8. EPSS: 3.5% chance of exploitation in the next 30 days.
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
Affected products
- b2evolution b2evolution: before 6.11.6 (fixed in 6.11.6)
Published 2021-02-09. Last modified 2026-06-17.