20
I Use This!
Very High Activity
Analyzed about 22 hours ago. based on code collected 2 days ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-50223 High Jun 10, 2026 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataRes more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-47342 High Jun 10, 2026 A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apach more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-46586 High May 19, 2026 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulne more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-45434 Critical May 19, 2026 Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-45187 Medium May 19, 2026 Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-41919 Critical May 19, 2026 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: b more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-35086 Medium May 19, 2026 Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24. more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-31986 Critical May 19, 2026 Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-31910 High May 19, 2026 Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06
CVE-2026-31909 High May 19, 2026 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are more...
18.12.06, 17.12.09, 18.12.05, 18.12.04, 18.12.03, 18.12.02, 18.12.01, 17.12.08, 17.12.07, 17.12.06