cbcvebase.
CVE-2025-30676
published 2025-04-01

CVE-2025-30676: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 18.12.1918.12.19
apacheofbiz
apache_software_foundationapache_ofbiz< 18.12.1918.12.19