Description b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. Remediation References CVE-2016-8901 Related Vulnerabilities WordPress Plugin DS.DownloadList PHP Object Injection (1.2) XWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2023-29510) WordPress Plugin Amazon Tools Cross-Site Scripting (1.7.2) WordPress Plugin bbPress Login Register Links On Forum Topic Pages Cross-Site Request Forgery (2.7.5) WordPress Plugin Browser Blocker Cross-Site Scripting (0.5.6) Severity Critical Classification CVE-2016-8901 CWE-138 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities