Apache Ofbiz vulnerabilities
73 known vulnerabilities affecting apache/ofbiz.
Total CVEs
73
CISA KEV
3
actively exploited
Public exploits
19
Exploited in wild
14
Severity breakdown
CRITICAL26HIGH19MEDIUM26LOW2
Vulnerabilities
Page 1 of 4
CVE-2024-32113P1CRITICALCVSS 9.8KEVPoCfixed in 18.12.132024-05-08
CVE-2024-32113 [CRITICAL] CWE-22 CVE-2024-32113: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.
Users are recommended to upgrade to version 18.12.13, which fixes the issue.
nvd
CVE-2024-38856P1CRITICALCVSS 9.8KEVPoCfixed in 18.12.152024-08-05
CVE-2024-38856 [CRITICAL] CWE-863 CVE-2024-38856: Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to version 18.12.15, which fixes the issue.
Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explici
nvd
CVE-2024-45195P1HIGHCVSS 7.5KEVPoCfixed in 18.12.162024-09-04
CVE-2024-45195 [HIGH] CWE-425 CVE-2024-45195: Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrade to version 18.12.16, which fixes the issue.
nvd
CVE-2023-51467P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.112023-12-26
CVE-2023-51467 [CRITICAL] CWE-918 CVE-2023-51467: The vulnerability permits attackers to circumvent authentication processes, enabling them to remotel
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
nvd
CVE-2021-26295P1CRITICALCVSS 9.8ExploitedPoCfixed in 17.12.062021-03-22
CVE-2021-26295 [CRITICAL] CWE-502 CVE-2021-26295: Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
nvd
CVE-2023-49070P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.102023-12-05
CVE-2023-49070 [CRITICAL] CWE-94 CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Users are recommended to upgrade to version 18.12.10
nvd
CVE-2024-45507P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.162024-09-04
CVE-2024-45507 [CRITICAL] CWE-94 CVE-2024-45507: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulner
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrade to version 18.12.16, which fixes the issue.
nvd
CVE-2024-36104P1CRITICALCVSS 9.1ExploitedPoCfixed in 18.12.142024-06-04
CVE-2024-36104 [CRITICAL] CWE-22 CVE-2024-36104: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14.
Users are recommended to upgrade to version 18.12.14, which fixes the issue.
nvd
CVE-2021-30128P1CRITICALCVSS 9.8ExploitedPoCfixed in 17.12.072021-04-27
CVE-2021-30128 [CRITICAL] CWE-502 CVE-2021-30128: Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
nvd
CVE-2020-9496P1MEDIUMCVSS 6.1ExploitedPoCv17.12.032020-07-15
CVE-2020-9496 [MEDIUM] CWE-79 CVE-2020-9496: XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache O
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
nvd
CVE-2020-1943P1MEDIUMCVSS 6.1ExploitedPoC≥ 16.11.01, ≤ 16.11.072020-04-01
CVE-2020-1943 [MEDIUM] CWE-79 CVE-2020-1943: Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 1
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
nvd
CVE-2023-50968P1HIGHCVSS 7.5ExploitedPoCfixed in 18.12.112023-12-26
CVE-2023-50968 [HIGH] CWE-200 CVE-2023-50968: Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations.
The same uri can be operated to realize a SSRF attack also without authorizations.
Users are recommended to upgrade to version 18.12.11, which fixes this issue.
nvd
CVE-2011-3600P1HIGHCVSS 7.5ExploitedPoC≥ 16.11.01, ≤ 16.11.042019-11-26
CVE-2011-3600 [HIGH] CWE-611 CVE-2011-3600: The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity I
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists o
nvd
CVE-2022-47501P2HIGHCVSS 7.5ExploitedPoCfixed in 18.12.072023-04-14
CVE-2022-47501 [HIGH] CWE-22 CVE-2022-47501: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
This issue affects Apache OFBiz: before 18.12.07.
nvd
CVE-2021-29200P2CRITICALCVSS 9.8PoCfixed in 17.12.072021-04-27
CVE-2021-29200 [CRITICAL] CWE-502 CVE-2021-29200: Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perfor
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
nvd
CVE-2019-0235P2HIGHCVSS 8.8PoCv17.12.012020-04-30
CVE-2019-0235 [HIGH] CWE-352 CVE-2019-0235: Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
nvd
CVE-2018-8033P2HIGHCVSS 7.5PoC≥ 16.11.01, ≤ 16.11.042018-12-13
CVE-2018-8033 [HIGH] CWE-200 CVE-2018-8033: In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEng
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by havi
nvd
CVE-2024-25065P2CRITICALCVSS 9.1fixed in 18.12.122024-02-29
CVE-2024-25065 [CRITICAL] CWE-22 CVE-2024-25065: Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upg
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
nvd
CVE-2026-45434P2CRITICALCVSS 9.8fixed in 24.09.062026-05-19
CVE-2026-45434 [CRITICAL] CWE-287 CVE-2026-45434: Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remo
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-54466P2CRITICALCVSS 9.8fixed in 24.09.022025-08-15
CVE-2025-54466 [CRITICAL] CWE-94 CVE-2025-54466: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the
nvd
1 / 4Next →