← Vulnerability feed

Vulnerability record · CVE-2022-25813 · published 2 September 2022

CVE-2022-25813: Apache OFBiz ecommerce plugin server-side template injection leads to RCE

Apache · Ofbiz

Apache OFBiz 18.12.05 and earlier allows an anonymous user of the ecommerce plugin to inject malicious content into the Subject field of the "Contact us" page. The payload is only executed when a party manager lists the communications in the party component, triggering server-side template injection that can lead to remote code execution.

7.5 CVSS 3.1 High EPSS 67% · top 0.7% CWE-1336 · CWE-1336CWE-94 · Code injection
7.5CVSS 3.1 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 7.5 with network reachability and no authentication, plus a very high EPSS score, though exploitation requires a party manager to view the communications list.

What it is

Apache OFBiz 18.12.05 and earlier allows an anonymous user of the ecommerce plugin to inject malicious content into the Subject field of the "Contact us" page. The payload is only executed when a party manager lists the communications in the party component, triggering server-side template injection that can lead to remote code execution.

Impact

An attacker can achieve remote code execution on the OFBiz server, gaining the ability to run arbitrary commands with the application's privileges.

Attack surface

Reachable over the network through the ecommerce plugin's "Contact us" page with no authentication required; a party manager must later view the communications list to activate the injection, so limited user interaction on the victim side is needed.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.67261 (99.3rd percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Upgrade Apache OFBiz to a version later than 18.12.05 that contains the fix referenced in the vendor advisory.
  • If immediate upgrade is not possible, restrict or disable the ecommerce plugin's "Contact us" page for anonymous users.
  • Sanitize and validate the Subject field input on the contact form before it is stored or rendered.
  • Limit access to the party component communications listing to trusted administrators only.
  • Monitor Apache OFBiz security advisories for follow-up patches or workarounds.

Detection

  • Review OFBiz logs for anomalous template expressions or code-like strings in contact form Subject fields.
  • Alert on unexpected child processes or command execution spawned by the OFBiz Java process.
  • Audit party component communication records for suspicious Subject content submitted from anonymous sessions.
  • Monitor for unusual outbound network connections from the OFBiz host following contact form submissions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25813 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-25813), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.