Apache Software Foundation Apache Ofbiz vulnerabilities
51 known vulnerabilities affecting apache_software_foundation/apache_ofbiz.
Total CVEs
51
CISA KEV
3
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL19HIGH15MEDIUM16LOW1
Vulnerabilities
Page 2 of 3
CVE-2026-50223P2HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-50223 [HIGH] CWE-94 CVE-2026-50223: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution.
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended to upgrade to version 24
nvd
CVE-2024-47208P3CRITICALCVSS 9.8fixed in 18.12.172024-11-18
CVE-2024-47208 [CRITICAL] CWE-94 CVE-2024-47208: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulner
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-47342P3HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-47342 [HIGH] CWE-285 CVE-2026-47342: A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended to upgrade to version 24.09.07, which fixes the issue.
nvd
CVE-2026-46586P3HIGHCVSS 8.8fixed in 24.09.062026-05-19
CVE-2026-46586 [HIGH] CWE-94 CVE-2026-46586: Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-30676P3MEDIUMCVSS 6.1fixed in 18.12.192025-04-01
CVE-2025-30676 [MEDIUM] CWE-80 CVE-2025-30676: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.19.
Users are recommended to upgrade to version 18.12.19, which fixes the issue.
nvd
CVE-2026-41919P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-41919 [CRITICAL] CWE-90 CVE-2026-41919: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31986P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-31986 [CRITICAL] CWE-321 CVE-2026-31986: Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2017-15714P3CRITICALCVSS 9.8v16.11.01 to 16.11.032018-01-04
CVE-2017-15714 [CRITICAL] CWE-74 CVE-2017-15714: The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. Thi
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
nvd
CVE-2025-59118P3HIGHCVSS 7.3fixed in 24.09.032025-11-12
CVE-2025-59118 [HIGH] CWE-434 CVE-2025-59118: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects A
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.03.
Users are recommended to upgrade to version 24.09.03, which fixes the issue.
nvd
CVE-2016-4462P3HIGHCVSS 8.8v13.07.*v12.04.*+1 more2017-08-30
CVE-2016-4462 [HIGH] CWE-20 CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Fre
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
nvd
CVE-2026-31910P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31910 [HIGH] CWE-918 CVE-2026-31910: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2024-48962P3HIGHCVSS 8.8fixed in 18.12.172024-11-18
CVE-2024-48962 [HIGH] CWE-94 CVE-2024-48962: Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Impr
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-29226P3HIGHCVSS 7.3fixed in 24.09.062026-05-19
CVE-2026-29226 [HIGH] CWE-918 CVE-2026-29226: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31909P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31909 [HIGH] CWE-200 CVE-2026-31909: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2022-29158P3HIGHCVSS 7.5≥ Apache OFBiz, ≤ 18.12.052022-09-02
CVE-2022-29158 [HIGH] CWE-1333 CVE-2022-29158: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in
Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599
nvd
CVE-2026-29220P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29220 [MEDIUM] CWE-22 CVE-2026-29220: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-29207P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29207 [MEDIUM] CWE-1336 CVE-2026-29207: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Please note that in the updated version, "Data Resource" records with dataTemplateTypeId = "FTL" are no longer supporte
nvd
CVE-2026-31378P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-31378 [MEDIUM] CWE-20 CVE-2026-31378: Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24
Improper Input Validation vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-35086P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-35086 [MEDIUM] CWE-94 CVE-2026-35086: Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-45187P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-45187 [MEDIUM] CWE-285 CVE-2026-45187: Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef
Improper Authorization vulnerability in Apache OFBiz Webtools.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd