Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache OFBiz — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in Apache OFBiz, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Apache OFBiz, a Java-based open-source business automation and e-commerce application. It collects a diverse set of flaws, including remote code execution, cross-site scripting, SQL injection, and deserialization issues, documenting advisories published over several years. Readers can track the vendor’s security advisories, analyze specific weakness classes, and review the product’s complete vulnerability history to assess risk exposure.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2024-32113 Apache OFBiz: Path traversal leading to RCE CWE-22 7.5AI High AI 2024-05-08
CVE-2024-23946 Apache OFBiz: Path traversal or file inclusion CWE-22 9.1 - 2024-02-28
CVE-2024-25065 Apache OFBiz: Path traversal allowing authentication bypass. CWE-22 9.1 - 2024-02-28
CVE-2023-51467 Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability 9.8AI Critical AI 2023-12-26
CVE-2023-50968 Apache OFBiz: Arbitrary file properties reading and SSRF attack CWE-200 6.5AI Medium AI 2023-12-26
CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present CWE-94 9.8 - 2023-12-05
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication CWE-306 9.8 - 2023-11-07
CVE-2022-47501 Apache OFBiz: Arbitrary file reading vulnerability CWE-22 7.5 - 2023-04-14
CVE-2022-29158 Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz CWE-1333 7.5 - 2022-09-02
CVE-2022-29063 Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz CWE-502 9.8 - 2022-09-02
CVE-2022-25813 Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz CWE-1336 7.5 - 2022-09-02
CVE-2022-25371 Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz CWE-22 9.8 - 2022-09-02
CVE-2022-25370 Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz CWE-79 5.4 - 2022-09-02
CVE-2021-37608 Arbitrary file upload vulnerability in OFBiz CWE-434 9.8 - 2021-08-18
CVE-2021-30128 Unsafe deserialization in Apache OFBiz 9.8 - 2021-04-27
CVE-2021-29200 RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI 9.8 - 2021-04-27
CVE-2021-26295 RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI 9.8 - 2021-03-22
CVE-2020-9496 Apache OFBiz 代码问题漏洞 8.8 - 2020-07-15
CVE-2020-13923 Apache OFBiz 输入验证错误漏洞 5.3 - 2020-07-15
CVE-2019-0235 Apache OFBiz 跨站请求伪造漏洞 8.8 - 2020-04-30
CVE-2019-12425 Apache OFBiz 注入漏洞 7.5 - 2020-04-30
CVE-2020-1943 Apache OFBiz 跨站脚本漏洞 6.1 - 2020-04-01
CVE-2019-12426 Apache OFBiz 信息泄露漏洞 5.3 - 2020-02-06
CVE-2018-8033 Apache OFBiz 安全漏洞 7.5 - 2018-12-13
CVE-2017-15714 Apache OFBiz BIRT插件安全漏洞 9.8 - 2018-01-04
CVE-2016-6800 Apache OFBiz 跨站脚本漏洞 6.1 - 2017-08-30
CVE-2016-4462 Apache OFBiz 安全漏洞 8.8 - 2017-08-30

All 57 known CVE vulnerabilities affecting Apache OFBiz with full Chinese analysis, references, and POCs where available.