|
Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
|---|---|---|---|---|---|
| CVE-2026-50223 | High | Jun 10, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataRes more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-47342 | High | Jun 10, 2026 | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apach more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-46586 | High | May 19, 2026 | Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulne more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-45434 | Critical | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-45187 | Medium | May 19, 2026 | Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-41919 | Critical | May 19, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: b more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-35086 | Medium | May 19, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24. more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-31986 | Critical | May 19, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-31910 | High | May 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|
|
| CVE-2026-31909 | High | May 19, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are more... |
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
|