Apache Ofbiz vulnerabilities
73 known vulnerabilities affecting apache/ofbiz.
Total CVEs
73
CISA KEV
3
actively exploited
Public exploits
19
Exploited in wild
14
Severity breakdown
CRITICAL26HIGH19MEDIUM26LOW2
Vulnerabilities
Page 3 of 4
CVE-2016-4462P3HIGHCVSS 8.8v11.04v11.04.01+16 more2017-08-30
CVE-2016-4462 [HIGH] CWE-20 CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Fre
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
nvd
CVE-2019-12425P3HIGHCVSS 7.5v17.12.012020-04-30
CVE-2019-12425 [HIGH] CWE-74 CVE-2019-12425: Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
nvd
CVE-2013-0177P4LOWCVSS 3.5PoCv09.04v09.04.01+6 more2014-01-30
CVE-2013-0177 [LOW] CWE-79 CVE-2013-0177: Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apach
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the par
nvd
CVE-2026-31910P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31910 [HIGH] CWE-918 CVE-2026-31910: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2024-48962P3HIGHCVSS 8.8fixed in 18.12.172024-11-18
CVE-2024-48962 [HIGH] CWE-94 CVE-2024-48962: Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Impr
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-29226P3HIGHCVSS 7.3fixed in 24.09.062026-05-19
CVE-2026-29226 [HIGH] CWE-918 CVE-2026-29226: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2021-25958P3HIGHCVSS 7.5≥ 17.12.01, < 17.12.082021-08-30
CVE-2021-25958 [HIGH] CWE-209 CVE-2021-25958: In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at
In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.
nvd
CVE-2012-3506P3CRITICALCVSS 10.0v10.04.01v10.04.022012-10-25
CVE-2012-3506 [CRITICAL] CVE-2012-3506: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.0
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
nvd
CVE-2026-31909P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31909 [HIGH] CWE-200 CVE-2026-31909: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2022-29158P3HIGHCVSS 7.5fixed in 18.12.062022-09-02
CVE-2022-29158 [HIGH] CWE-1333 CVE-2022-29158: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in
Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599
nvd
CVE-2026-29220P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29220 [MEDIUM] CWE-22 CVE-2026-29220: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-29207P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29207 [MEDIUM] CWE-1336 CVE-2026-29207: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Please note that in the updated version, "Data Resource" records with dataTemplateTypeId = "FTL" are no longer supporte
nvd
CVE-2026-31378P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-31378 [MEDIUM] CWE-20 CVE-2026-31378: Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24
Improper Input Validation vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-35086P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-35086 [MEDIUM] CWE-94 CVE-2026-35086: Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-45187P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-45187 [MEDIUM] CWE-285 CVE-2026-45187: Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef
Improper Authorization vulnerability in Apache OFBiz Webtools.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31380P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-31380 [MEDIUM] CWE-917 CVE-2026-31380: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-61623P3MEDIUMCVSS 6.5fixed in 24.09.032025-11-12
CVE-2025-61623 [MEDIUM] CWE-79 CVE-2025-61623: Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befo
Reflected cross-site scripting vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommended to upgrade to version 24.09.03, which fixes the issue.
nvd
CVE-2015-3268P4MEDIUMCVSS 6.1v12.04.01v12.04.02+5 more2016-04-12
CVE-2015-3268 [MEDIUM] CWE-79 CVE-2015-3268: Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFor
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
nvd
CVE-2024-23946P4MEDIUMCVSS 5.3fixed in 18.12.122024-02-29
CVE-2024-23946 [MEDIUM] CWE-22 CVE-2024-23946: Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to
Possible path traversal in Apache OFBiz allowing file inclusion.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
nvd
CVE-2019-12426P4MEDIUMCVSS 5.3≥ 16.11.01, ≤ 16.11.062020-02-06
CVE-2019-12426 [MEDIUM] CVE-2019-12426: an unauthenticated user could get access to information of some backend screens by invoking setSessi
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
nvd