VendorsApacheofbizall versions
Vulnerabilities

Apache Software Foundation OFBiz

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2021-30128
Unsafe deserialization in Apache OFBiz
Published 2021-04-27 · Modified
10.0EPSS 0.812
CVE-2013-2250
Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
Published 2013-08-15 · Modified
10.0EPSS 0.121
CVE-2012-3506
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
Published 2012-10-25 · Modified
10.0EPSS 0.075
CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
Published 2024-09-04 · Analyzed
9.8KEVEPSS 1.000
CVE-2024-32113
Apache OFBiz: Path traversal leading to RCE
Published 2024-05-08 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
Published 2024-08-05 · Analyzed
9.8KEVEPSS 0.994
CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
Published 2021-03-22 · Modified
9.8EPSS 0.978
CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
Published 2023-12-26 · Modified
9.8EPSS 0.960
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
Published 2023-12-05 · Modified
9.8EPSS 0.954
CVE-2024-45507
Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
Published 2024-09-04 · Modified
9.8EPSS 0.932
CVE-2021-29200
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
Published 2021-04-27 · Modified
9.8EPSS 0.554
CVE-2019-0189
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16
Published 2019-09-11 · Modified
9.8EPSS 0.237
CVE-2025-54466
Apache OFBiz: RCE Vulnerability in scrum plugin
Published 2025-08-15 · Modified
9.8EPSS 0.173
CVE-2016-2170
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Published 2016-04-12 · Modified
9.8EPSS 0.127
CVE-2021-37608
Arbitrary file upload vulnerability in OFBiz
Published 2021-08-18 · Modified
9.8EPSS 0.060
CVE-2022-25371
Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz
Published 2022-09-02 · Modified
9.8EPSS 0.051
CVE-2018-17200
The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019
Published 2019-09-11 · Modified
9.8EPSS 0.050
CVE-2012-1622
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2017-10-26 · Modified
9.8EPSS 0.050
CVE-2022-29063
Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz
Published 2022-09-02 · Modified
9.8EPSS 0.048
CVE-2019-10074
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533
Published 2019-09-11 · Modified
9.8EPSS 0.034
CVE-2017-15714
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
Published 2018-01-04 · Modified
9.8EPSS 0.033
CVE-2024-47208
Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE
Published 2024-11-18 · Analyzed
9.8EPSS 0.016
CVE-2026-45434
Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE
Published 2026-05-19 · Modified
9.8EPSS 0.013
CVE-2024-36104
Apache OFBiz: Path traversal leading to a RCE
Published 2024-06-04 · Analyzed
9.1EPSS 0.879
CVE-2024-25065
Apache OFBiz: Path traversal allowing authentication bypass.
Published 2024-02-28 · Analyzed
9.1EPSS 0.477
CVE-2026-41919
Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
Published 2026-05-19 · Modified
9.1EPSS 0.006
CVE-2026-31986
Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
Published 2026-05-19 · Modified
9.1EPSS 0.006
CVE-2024-48962
Apache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)
Published 2024-11-18 · Analyzed
8.9EPSS 0.006
CVE-2019-0235
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Published 2020-04-30 · Modified
8.81 PoCEPSS 0.327
CVE-2016-4462
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
Published 2017-08-30 · Modified
8.8EPSS 0.038
CVE-2026-50223
Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
Published 2026-06-10 · Analyzed
8.8EPSS 0.011
CVE-2026-46586
Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution
Published 2026-05-19 · Modified
8.8EPSS 0.007
CVE-2026-47342
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
Published 2026-06-10 · Analyzed
8.8EPSS 0.006
CVE-2022-25813
Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz
Published 2022-09-02 · Modified
7.5EPSS 0.673
CVE-2023-50968
Apache OFBiz: Arbitrary file properties reading and SSRF attack
Published 2023-12-26 · Modified
7.5EPSS 0.634
CVE-2018-8033
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.
Published 2018-12-13 · Modified
7.5EPSS 0.257
CVE-2011-3600
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Published 2019-11-26 · Modified
7.5EPSS 0.159
CVE-2022-47501
Apache OFBiz: Arbitrary file reading vulnerability
Published 2023-04-14 · Modified
7.5EPSS 0.102
CVE-2019-12425
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Published 2020-04-30 · Modified
7.5EPSS 0.048
CVE-2021-25958
Generation of Error Message Containing Sensitive Information in Apache OFBiz
Published 2021-08-30 · Modified
7.5EPSS 0.026
1 / 2Next →