cbcvebase.

Apache Ofbiz vulnerabilities

73 known vulnerabilities affecting apache/ofbiz.

Total CVEs
73
CISA KEV
3
actively exploited
Public exploits
19
Exploited in wild
14
Severity breakdown
CRITICAL26HIGH19MEDIUM26LOW2

Vulnerabilities

Page 2 of 4
CVE-2022-25813P2HIGHCVSS 7.5fixed in 18.12.062022-09-02
CVE-2022-25813 [HIGH] CWE-1336 CVE-2022-25813: In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecomm In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
nvd
CVE-2019-0189P2CRITICALCVSS 9.8≥ 16.11.01, < 16.11.06vOFBiz 16.11.01 to 16.11.052019-09-11
CVE-2019-0189 [CRITICAL] CWE-502 CVE-2019-0189: The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is expose The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affe
nvd
CVE-2016-2170P2CRITICALCVSS 9.8≥ 12.04, < 12.04.06≥ 13.07, < 13.07.032016-04-12
CVE-2016-2170 [CRITICAL] CWE-20 CVE-2016-2170: Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute a Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
nvd
CVE-2021-37608P2CRITICALCVSS 9.8fixed in 17.12.082021-08-18
CVE-2021-37608 [CRITICAL] CWE-434 CVE-2021-37608: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.
nvd
CVE-2022-25371P2CRITICALCVSS 9.8fixed in 18.12.062022-09-02
CVE-2022-25371 [CRITICAL] CWE-22 CVE-2022-25371: Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data v Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.
nvd
CVE-2022-29063P2CRITICALCVSS 9.8fixed in 18.12.062022-09-02
CVE-2022-29063 [CRITICAL] CWE-502 CVE-2022-29063: The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on loca The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or appl
nvd
CVE-2026-50223P2HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-50223 [HIGH] CWE-94 CVE-2026-50223: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24
nvd
CVE-2013-2250P3CRITICALCVSS 10.0v10.04.01v10.04.02+6 more2013-08-15
CVE-2013-2250 [CRITICAL] CWE-20 CVE-2013-2250: Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, a Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
nvd
CVE-2012-1622P3CRITICALCVSS 9.8v10.042017-10-26
CVE-2012-1622 [CRITICAL] CVE-2012-1622: Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecifi Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2018-17200P3CRITICALCVSS 9.8≥ 16.11.01, ≤ 16.11.05vOFBiz 16.11.01 to 16.11.052019-09-11
CVE-2018-17200 [CRITICAL] CVE-2018-17200: The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. Howev
nvd
CVE-2024-47208P3CRITICALCVSS 9.8fixed in 18.12.172024-11-18
CVE-2024-47208 [CRITICAL] CWE-94 CVE-2024-47208: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulner Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-47342P3HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-47342 [HIGH] CWE-285 CVE-2026-47342: A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
nvd
CVE-2026-46586P3HIGHCVSS 8.8fixed in 24.09.062026-05-19
CVE-2026-46586 [HIGH] CWE-94 CVE-2026-46586: Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-30676P3MEDIUMCVSS 6.1fixed in 18.12.192025-04-01
CVE-2025-30676 [MEDIUM] CWE-80 CVE-2025-30676: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.
nvd
CVE-2026-41919P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-41919 [CRITICAL] CWE-90 CVE-2026-41919: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31986P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-31986 [CRITICAL] CWE-321 CVE-2026-31986: Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2019-10074P3CRITICALCVSS 9.8≥ 16.11.01, ≤ 16.11.05vOFBiz 16.11.01 to 16.11.052019-09-11
CVE-2019-10074 [CRITICAL] CWE-74 CVE-2019-10074: An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Up
nvd
CVE-2017-15714P3CRITICALCVSS 9.8v16.11.01v16.11.02+1 more2018-01-04
CVE-2017-15714 [CRITICAL] CWE-74 CVE-2017-15714: The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. Thi The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
nvd
CVE-2010-0432P4MEDIUMCVSS 4.3PoC≤ 09.042010-04-15
CVE-2010-0432 [MEDIUM] CWE-79 CVE-2010-0432: Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFB Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewpro
nvd
CVE-2025-59118P3HIGHCVSS 7.3fixed in 24.09.032025-11-12
CVE-2025-59118 [HIGH] CWE-434 CVE-2025-59118: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects A Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.
nvd
Apache Ofbiz vulnerabilities | cvebase