Ofbiz

Apache · 76 CVEs

CVE-2026-47342
HIGH

Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass

Jun 10, 2026

CVE-2026-50223
HIGH

Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution

Jun 10, 2026

CVE-2026-46586
HIGH

Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution

May 19, 2026

CVE-2026-45434
CRITICAL

Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE

May 19, 2026

CVE-2026-45187
MEDIUM

Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs

May 19, 2026

CVE-2026-41919
CRITICAL

Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction

May 19, 2026

CVE-2026-35086
MEDIUM

Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services

May 19, 2026

CVE-2026-31986
CRITICAL

Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection

May 19, 2026

CVE-2026-31910
HIGH

Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access

May 19, 2026

CVE-2026-31909
HIGH

Apache OFBiz: Unauthenticated Shipment Label Image Disclosure

May 19, 2026

CVE-2026-31906
MEDIUM

Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters

May 19, 2026

CVE-2026-31388
MEDIUM

Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature

May 19, 2026

CVE-2026-31387
MEDIUM

Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation

May 19, 2026

CVE-2026-31380
MEDIUM

Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass

May 19, 2026

CVE-2026-31379
MEDIUM

Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in C…

May 19, 2026

CVE-2026-31378
MEDIUM

Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution

May 19, 2026

CVE-2026-29226
HIGH

Apache OFBiz: Low-Privilege SSRF in Content Component

May 19, 2026

CVE-2026-29207
MEDIUM

Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component

May 19, 2026

CVE-2026-29220
MEDIUM

Apache OFBiz: Low-Privilege LFI in Content Component

May 19, 2026

CVE-2025-61623
MEDIUM

Apache OFBiz: Reflected Cross-site Scripting

Nov 12, 2025

CVE-2025-59118
HIGH

Apache OFBiz: Critical Remote Command Execution via Unrestricted File Upload

Nov 12, 2025

CVE-2025-54466
CRITICAL

Apache OFBiz: RCE Vulnerability in scrum plugin

Aug 15, 2025

CVE-2025-30676
MEDIUM

Apache OFBiz: Stored XSS Vulnerability

Apr 1, 2025

CVE-2025-26865
LOW

Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE

Mar 10, 2025

CVE-2024-47208
CRITICAL

Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE

Nov 18, 2024

Showing 1 to 25 of 76 CVEs