This issue affects Apache OFBiz: before 18.12.19.
Users are recommended to upgrade to version 18.12.19, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9281 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 29 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache ofbiz |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache ofbiz |
Wed, 02 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 01 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue. | |
| Title | Apache OFBiz: Stored XSS Vulnerability | |
| Weaknesses | CWE-80 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-02T22:03:27.945Z
Reserved: 2025-03-25T07:44:43.788Z
Link: CVE-2025-30676
Updated: 2025-04-02T22:03:27.945Z
Status : Analyzed
Published: 2025-04-01T15:16:07.310
Modified: 2025-04-29T20:52:31.980
Link: CVE-2025-30676
No data.
OpenCVE Enrichment
No data.
EUVD