Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache OFBiz — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in Apache OFBiz, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities associated with the Apache OFBiz application framework, categorized under common weakness enumeration tags. It aggregates vulnerability data specifically related to this open-source enterprise resource planning and e-commerce platform developed by the Apache Software Foundation. The collection includes a wide range of security flaws, such as cross-site scripting, SQL injection, authentication bypasses, and file inclusion errors. The data spans from the early 2000s through the present day, covering the entire historical lifespan of the software’s major releases and security patches. Readers can use this resource to track vendor advisories issued by the Apache Project, understand the prevalence and impact of specific weakness classes within this particular codebase, and look up the detailed vulnerability history of Apache OFBiz. This comprehensive overview helps security professionals assess risk exposure by providing context on how often specific types of vulnerabilities have affected the product over time. By centralizing this information, the page facilitates deeper analysis of the software’s security posture and aids in identifying trends in defect discovery and remediation. It serves as a historical record for auditing purposes and helps organizations understand the evolution of security practices within the Apache OFBiz ecosystem. This resource is intended for developers, security analysts, and IT administrators who need to evaluate the current state of known issues.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2024-32113 Apache OFBiz: Path traversal leading to RCE CWE-22 7.5AIHighAI2024-05-08
CVE-2024-23946 Apache OFBiz: Path traversal or file inclusion CWE-22 9.1 -2024-02-28
CVE-2024-25065 Apache OFBiz: Path traversal allowing authentication bypass. CWE-22 9.1 -2024-02-28
CVE-2023-51467 Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability 9.8AICriticalAI2023-12-26
CVE-2023-50968 Apache OFBiz: Arbitrary file properties reading and SSRF attack CWE-200 6.5AIMediumAI2023-12-26
CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present CWE-94 9.8 -2023-12-05
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication CWE-306 9.8 -2023-11-07
CVE-2022-47501 Apache OFBiz: Arbitrary file reading vulnerability CWE-22 7.5 -2023-04-14
CVE-2022-29158 Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz CWE-1333 7.5 -2022-09-02
CVE-2022-29063 Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz CWE-502 9.8 -2022-09-02
CVE-2022-25813 Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz CWE-1336 7.5 -2022-09-02
CVE-2022-25371 Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz CWE-22 9.8 -2022-09-02
CVE-2022-25370 Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz CWE-79 5.4 -2022-09-02
CVE-2021-37608 Arbitrary file upload vulnerability in OFBiz CWE-434 9.8 -2021-08-18
CVE-2021-30128 Unsafe deserialization in Apache OFBiz 9.8 -2021-04-27
CVE-2021-29200 RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI 9.8 -2021-04-27
CVE-2021-26295 RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI 9.8 -2021-03-22
CVE-2020-9496 Apache OFBiz 代码问题漏洞 8.8 -2020-07-15
CVE-2020-13923 Apache OFBiz 输入验证错误漏洞 5.3 -2020-07-15
CVE-2019-0235 Apache OFBiz 跨站请求伪造漏洞 8.8 -2020-04-30
CVE-2019-12425 Apache OFBiz 注入漏洞 7.5 -2020-04-30
CVE-2020-1943 Apache OFBiz 跨站脚本漏洞 6.1 -2020-04-01
CVE-2019-12426 Apache OFBiz 信息泄露漏洞 5.3 -2020-02-06
CVE-2018-8033 Apache OFBiz 安全漏洞 7.5 -2018-12-13
CVE-2017-15714 Apache OFBiz BIRT插件安全漏洞 9.8 -2018-01-04
CVE-2016-6800 Apache OFBiz 跨站脚本漏洞 6.1 -2017-08-30
CVE-2016-4462 Apache OFBiz 安全漏洞 8.8 -2017-08-30

All 57 known CVE vulnerabilities affecting Apache OFBiz with full Chinese analysis, references, and POCs where available.