Apache Ofbiz vulnerabilities
73 known vulnerabilities affecting apache/ofbiz.
Total CVEs
73
CISA KEV
4
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH17MEDIUM27LOW2UNKNOWN1
Vulnerabilities
Page 4 of 4
CVE-2016-4462HIGHCVSS 8.8v11.04v11.04.01+16 more2017-08-30
CVE-2016-4462 [HIGH] CWE-20 CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Fre
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
nvdapache
CVE-2016-6800MEDIUMCVSS 6.1v11.04v11.04.01+16 more2017-08-30
CVE-2016-6800 [MEDIUM] CWE-79 CVE-2016-6800: The default configuration of the Apache OFBiz framework offers a blog functionality. Different users
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaS
nvdapache
CVE-2016-2170CRITICALCVSS 9.8≥ 12.04, < 12.04.06≥ 13.07, < 13.07.032016-04-12
CVE-2016-2170 [CRITICAL] CWE-20 CVE-2016-2170: Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute a
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
nvdapache
CVE-2015-3268MEDIUMCVSS 6.1v12.04.01v12.04.02+5 more2016-04-12
CVE-2015-3268 [MEDIUM] CWE-79 CVE-2015-3268: Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFor
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
nvdapache
CVE-2014-0232MEDIUMCVSS 4.3v12.04.01v12.04.02+5 more2014-08-22
CVE-2014-0232 [MEDIUM] CWE-79 CVE-2014-0232: Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.
nvdapache
CVE-2012-1621MEDIUMCVSS 4.3v10.04.012014-06-19
CVE-2012-1621 [MEDIUM] CWE-79 CVE-2012-1621: Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz)
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message,
nvdapache
CVE-2013-0177LOWCVSS 3.5PoCv09.04v09.04.01+6 more2014-01-30
CVE-2013-0177 [LOW] CWE-79 CVE-2013-0177: Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apach
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the par
nvdapache
CVE-2013-2250CRITICALCVSS 10.0v10.04.01v10.04.02+6 more2013-08-15
CVE-2013-2250 [CRITICAL] CWE-20 CVE-2013-2250: Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, a
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
nvdapache
CVE-2013-2137MEDIUMCVSS 4.3v10.04.01v10.04.02+6 more2013-08-15
CVE-2013-2137 [MEDIUM] CWE-79 CVE-2013-2137: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apa
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvdapache
CVE-2012-3506CRITICALCVSS 10.0v10.04.01v10.04.022012-10-25
CVE-2012-3506 [CRITICAL] CVE-2012-3506: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.0
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
nvdapache
CVE-2010-0432MEDIUMCVSS 4.3PoC≤ 09.042010-04-15
CVE-2010-0432 [MEDIUM] CWE-79 CVE-2010-0432: Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFB
Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewpro
nvdapache
CVE-2021-45105MEDIUMCVSS 5.9
CVE-2021-45105 [MEDIUM] Apache ofbiz: CVE-2021-45105
Apache ofbiz: CVE-2021-45105
; affected all releases before 17.12.09 and 18.12.04; fixed in 17.12.09 and 18.12.04 with commits 00896e7 , c69bc8f , 4442c2a
apache
CVE-2021-44228UNKNOWNKEVPoC
CVE-2021-44228 Apache ofbiz: CVE-2021-44228
Apache ofbiz: CVE-2021-44228
; affected all releases before 17.12.09 and 18.12.03; fixed in 17.12.09 and 18.12.03 with commits 00896e7 , c69bc8f , bccf140
apache
← Previous4 / 4