CVE-2025-30676
published 2025-04-01CVE-2025-30676: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19…
PriorityP345medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
65.35%
99.2th percentile
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.19.
Users are recommended to upgrade to version 18.12.19, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.19 | 18.12.19 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | < 18.12.19 | 18.12.19 |
Detection & IOCsextracted from sources · hover to see the quote
- →Apache OFBiz versions before 18.12.19 are vulnerable to Basic XSS (Improper Neutralization of Script-Related HTML Tags). Detect exploitation attempts by monitoring for script-related HTML tag injection in OFBiz web requests. ↗
- →The vulnerability was fixed in Apache OFBiz 18.12.19 via commits ddfe3727b1, e7b7ae0eaa, and dba044c706. Reviewing these commits can help identify the affected code paths and craft targeted detection logic. ↗
- ·All Apache OFBiz deployments running versions before 18.12.19 are affected. Upgrade to 18.12.19 or later to remediate. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_apache6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2025-30676
vendor_apache·CVSS 6.1
CVE-2025-30676 [MEDIUM] Apache ofbiz: CVE-2025-30676
Apache ofbiz: CVE-2025-30676
; affected releases before 18.12.19; fixed in 18.12.19 with commits ddfe3727b1 , e7b7ae0eaa , dba044c706
GHSA
GHSA-vhg6-m6c8-39c2: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz
ghsa_unreviewed·2025-04-01
CVE-2025-30676 [MEDIUM] CWE-79 GHSA-vhg6-m6c8-39c2: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.19.
Users are recommended to upgrade to version 18.12.19, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-01
Published