Apache / Ofbiz
76 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-47342 | Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass | HIGH | 8.8 | Jun 10, 2026 |
| CVE-2026-50223 | Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution | HIGH | 8.8 | Jun 10, 2026 |
| CVE-2026-46586 | Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution | HIGH | 8.8 | May 19, 2026 |
| CVE-2026-45434 | Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE | CRITICAL | 9.8 | May 19, 2026 |
| CVE-2026-45187 | Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2026-41919 | Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction | CRITICAL | 9.1 | May 19, 2026 |
| CVE-2026-35086 | Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2026-31986 | Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection | CRITICAL | 9.1 | May 19, 2026 |
| CVE-2026-31910 | Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access | HIGH | 7.5 | May 19, 2026 |
| CVE-2026-31909 | Apache OFBiz: Unauthenticated Shipment Label Image Disclosure | HIGH | 7.5 | May 19, 2026 |
| CVE-2026-31906 | Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters | MEDIUM | 6.1 | May 19, 2026 |
| CVE-2026-31388 | Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature | MEDIUM | 5.3 | May 19, 2026 |
| CVE-2026-31387 | Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation | MEDIUM | 5.3 | May 19, 2026 |
| CVE-2026-31380 | Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2026-31379 | Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog Manager | MEDIUM | 6.1 | May 19, 2026 |
| CVE-2026-31378 | Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2026-29226 | Apache OFBiz: Low-Privilege SSRF in Content Component | HIGH | 7.3 | May 19, 2026 |
| CVE-2026-29207 | Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2026-29220 | Apache OFBiz: Low-Privilege LFI in Content Component | MEDIUM | 6.5 | May 19, 2026 |
| CVE-2025-61623 | Apache OFBiz: Reflected Cross-site Scripting | MEDIUM | 6.5 | Nov 12, 2025 |
| CVE-2025-59118 | Apache OFBiz: Critical Remote Command Execution via Unrestricted File Upload | HIGH | 7.3 | Nov 12, 2025 |
| CVE-2025-54466 | Apache OFBiz: RCE Vulnerability in scrum plugin | CRITICAL | 9.8 | Aug 15, 2025 |
| CVE-2025-30676 | Apache OFBiz: Stored XSS Vulnerability | MEDIUM | 6.1 | Apr 1, 2025 |
| CVE-2025-26865 | Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE | LOW | 3.5 | Mar 10, 2025 |
| CVE-2024-47208 | Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE | CRITICAL | 9.8 | Nov 18, 2024 |
Showing 1 to 25 of 76 CVEs