Ofbiz
Apache · 76 CVEs
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
Jun 10, 2026
Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
Jun 10, 2026
Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution
May 19, 2026
Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE
May 19, 2026
Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs
May 19, 2026
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
May 19, 2026
Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services
May 19, 2026
Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
May 19, 2026
Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access
May 19, 2026
Apache OFBiz: Unauthenticated Shipment Label Image Disclosure
May 19, 2026
Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters
May 19, 2026
Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature
May 19, 2026
Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation
May 19, 2026
Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass
May 19, 2026
Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in C…
May 19, 2026
Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution
May 19, 2026
Apache OFBiz: Low-Privilege SSRF in Content Component
May 19, 2026
Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component
May 19, 2026
Apache OFBiz: Low-Privilege LFI in Content Component
May 19, 2026
Apache OFBiz: Reflected Cross-site Scripting
Nov 12, 2025
Apache OFBiz: Critical Remote Command Execution via Unrestricted File Upload
Nov 12, 2025
Apache OFBiz: RCE Vulnerability in scrum plugin
Aug 15, 2025
Apache OFBiz: Stored XSS Vulnerability
Apr 1, 2025
Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE
Mar 10, 2025
Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE
Nov 18, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-47342 | Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass | HIGH | 0.58% | Jun 10, 2026 |
| CVE-2026-50223 | Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution | HIGH | 1.10% | Jun 10, 2026 |
| CVE-2026-46586 | Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution | HIGH | 0.71% | May 19, 2026 |
| CVE-2026-45434 | Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE | CRITICAL | 1.29% | May 19, 2026 |
| CVE-2026-45187 | Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs | MEDIUM | 0.65% | May 19, 2026 |
| CVE-2026-41919 | Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction | CRITICAL | 0.59% | May 19, 2026 |
| CVE-2026-35086 | Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services | MEDIUM | 0.63% | May 19, 2026 |
| CVE-2026-31986 | Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection | CRITICAL | 0.56% | May 19, 2026 |
| CVE-2026-31910 | Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access | HIGH | 0.58% | May 19, 2026 |
| CVE-2026-31909 | Apache OFBiz: Unauthenticated Shipment Label Image Disclosure | HIGH | 0.61% | May 19, 2026 |
| CVE-2026-31906 | Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters | MEDIUM | 0.57% | May 19, 2026 |
| CVE-2026-31388 | Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature | MEDIUM | 0.54% | May 19, 2026 |
| CVE-2026-31387 | Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation | MEDIUM | 0.60% | May 19, 2026 |
| CVE-2026-31380 | Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass | MEDIUM | 0.63% | May 19, 2026 |
| CVE-2026-31379 | Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog Manager | MEDIUM | 0.70% | May 19, 2026 |
| CVE-2026-31378 | Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution | MEDIUM | 0.67% | May 19, 2026 |
| CVE-2026-29226 | Apache OFBiz: Low-Privilege SSRF in Content Component | HIGH | 0.61% | May 19, 2026 |
| CVE-2026-29207 | Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component | MEDIUM | 0.63% | May 19, 2026 |
| CVE-2026-29220 | Apache OFBiz: Low-Privilege LFI in Content Component | MEDIUM | 0.80% | May 19, 2026 |
| CVE-2025-61623 | Apache OFBiz: Reflected Cross-site Scripting | MEDIUM | 0.78% | Nov 12, 2025 |
| CVE-2025-59118 | Apache OFBiz: Critical Remote Command Execution via Unrestricted File Upload | HIGH | 1.63% | Nov 12, 2025 |
| CVE-2025-54466 | Apache OFBiz: RCE Vulnerability in scrum plugin | CRITICAL | 17.32% | Aug 15, 2025 |
| CVE-2025-30676 | Apache OFBiz: Stored XSS Vulnerability | MEDIUM | 67.61% | Apr 1, 2025 |
| CVE-2025-26865 | Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE | LOW | 0.67% | Mar 10, 2025 |
| CVE-2024-47208 | Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE | CRITICAL | 1.60% | Nov 18, 2024 |
Showing 1 to 25 of 76 CVEs