cbcvebase.

Apache Software Foundation Apache Ofbiz vulnerabilities

51 known vulnerabilities affecting apache_software_foundation/apache_ofbiz.

Total CVEs
51
CISA KEV
3
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL19HIGH15MEDIUM16LOW1

Vulnerabilities

Page 2 of 3
CVE-2026-50223P2HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-50223 [HIGH] CWE-94 CVE-2026-50223: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24
nvd
CVE-2024-47208P3CRITICALCVSS 9.8fixed in 18.12.172024-11-18
CVE-2024-47208 [CRITICAL] CWE-94 CVE-2024-47208: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulner Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-47342P3HIGHCVSS 8.8fixed in 24.09.072026-06-10
CVE-2026-47342 [HIGH] CWE-285 CVE-2026-47342: A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
nvd
CVE-2026-46586P3HIGHCVSS 8.8fixed in 24.09.062026-05-19
CVE-2026-46586 [HIGH] CWE-94 CVE-2026-46586: Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-30676P3MEDIUMCVSS 6.1fixed in 18.12.192025-04-01
CVE-2025-30676 [MEDIUM] CWE-80 CVE-2025-30676: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.
nvd
CVE-2026-41919P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-41919 [CRITICAL] CWE-90 CVE-2026-41919: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31986P3CRITICALCVSS 9.1fixed in 24.09.062026-05-19
CVE-2026-31986 [CRITICAL] CWE-321 CVE-2026-31986: Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2017-15714P3CRITICALCVSS 9.8v16.11.01 to 16.11.032018-01-04
CVE-2017-15714 [CRITICAL] CWE-74 CVE-2017-15714: The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. Thi The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
nvd
CVE-2025-59118P3HIGHCVSS 7.3fixed in 24.09.032025-11-12
CVE-2025-59118 [HIGH] CWE-434 CVE-2025-59118: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects A Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.
nvd
CVE-2016-4462P3HIGHCVSS 8.8v13.07.*v12.04.*+1 more2017-08-30
CVE-2016-4462 [HIGH] CWE-20 CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Fre By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
nvd
CVE-2026-31910P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31910 [HIGH] CWE-918 CVE-2026-31910: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2024-48962P3HIGHCVSS 8.8fixed in 18.12.172024-11-18
CVE-2024-48962 [HIGH] CWE-94 CVE-2024-48962: Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Impr Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
nvd
CVE-2026-29226P3HIGHCVSS 7.3fixed in 24.09.062026-05-19
CVE-2026-29226 [HIGH] CWE-918 CVE-2026-29226: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-31909P3HIGHCVSS 7.5fixed in 24.09.062026-05-19
CVE-2026-31909 [HIGH] CWE-200 CVE-2026-31909: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2022-29158P3HIGHCVSS 7.5≥ Apache OFBiz, ≤ 18.12.052022-09-02
CVE-2022-29158 [HIGH] CWE-1333 CVE-2022-29158: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599
nvd
CVE-2026-29220P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29220 [MEDIUM] CWE-22 CVE-2026-29220: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-29207P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-29207 [MEDIUM] CWE-1336 CVE-2026-29207: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updated version, "Data Resource" records with dataTemplateTypeId = "FTL" are no longer supporte
nvd
CVE-2026-31378P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-31378 [MEDIUM] CWE-20 CVE-2026-31378: Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24 Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-35086P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-35086 [MEDIUM] CWE-94 CVE-2026-35086: Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2026-45187P3MEDIUMCVSS 6.5fixed in 24.09.062026-05-19
CVE-2026-45187 [MEDIUM] CWE-285 CVE-2026-45187: Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
Apache Software Foundation Apache Ofbiz vulnerabilities | cvebase