Apache
Apache Ofbiz: vulnerabilidades y CVE
Apache Ofbiz tiene 76 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 24 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE76
Últimos 12 meses21
Críticas24
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-45195 | Alta (7.5) | 100% | ⚠ Explotación activa | 4 sept 2024 | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. |
| CVE-2024-38856 | Crítica (9.8) | 99% | ⚠ Explotación activa | 5 ago 2024 | Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could… |
| CVE-2024-32113 | Crítica (9.8) | 100% | ⚠ Explotación activa | 8 may 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-50223 | Alta (8.8) | 1.1% | — | 10 jun 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that… |
| CVE-2026-47342 | Alta (8.8) | 0.58% | — | 10 jun 2026 | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version… |
| CVE-2026-46586 | Alta (8.8) | 0.71% | — | 19 may 2026 | Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… |
| CVE-2026-45434 | Crítica (9.8) | 1.3% | — | 19 may 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version… |
| CVE-2026-45187 | Media (6.5) | 0.65% | — | 19 may 2026 | Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-41919 | Crítica (9.1) | 0.59% | — | 19 may 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06,… |
| CVE-2026-35086 | Media (6.5) | 0.63% | — | 19 may 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which… |
| CVE-2026-31986 | Crítica (9.1) | 0.56% | — | 19 may 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-31910 | Alta (7.5) | 0.58% | — | 19 may 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-31909 | Alta (7.5) | 0.61% | — | 19 may 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-31906 | Media (6.1) | 0.57% | — | 19 may 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06,… |
| CVE-2026-31388 | Media (5.3) | 0.54% | — | 19 may 2026 | Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-31387 | Media (5.3) | 0.60% | — | 19 may 2026 | Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-31380 | Media (6.5) | 0.63% | — | 19 may 2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are… |
| CVE-2026-31379 | Media (6.1) | 0.70% | — | 19 may 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code… |
| CVE-2026-31378 | Media (6.5) | 0.67% | — | 19 may 2026 | Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. |
| CVE-2026-29226 | Alta (7.3) | 0.61% | — | 19 may 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the… |
| CVE-2026-29220 | Media (6.5) | 0.80% | — | 19 may 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which… |
| CVE-2026-29207 | Media (6.5) | 0.63% | — | 19 may 2026 | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes… |
| CVE-2025-61623 | Media (6.5) | 0.78% | — | 12 nov 2025 | Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. |
| CVE-2025-59118 | Alta (7.3) | 1.6% | — | 12 nov 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. |
| CVE-2025-54466 | Crítica (9.8) | 17% | — | 15 ago 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even… |
| CVE-2025-30676 | Media (6.1) | 68% | — | 1 abr 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which… |
| CVE-2025-26865 | Baja (3.5) | 0.65% | — | 10 mar 2025 | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In… |
| CVE-2024-48962 | Alta (8.9) | 0.61% | — | 18 nov 2024 | Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects… |
| CVE-2024-47208 | Crítica (9.8) | 1.6% | — | 18 nov 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version… |
| CVE-2024-45507 | Crítica (9.8) | 93% | — | 4 sept 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version… |
| CVE-2024-45195 | Alta (7.5) | 100% | ⚠ Explotación activa | 4 sept 2024 | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. |
| CVE-2024-38856 | Crítica (9.8) | 99% | ⚠ Explotación activa | 5 ago 2024 | Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could… |
| CVE-2024-36104 | Crítica (9.1) | 88% | — | 4 jun 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.