← Vulnerability feed

Vulnerability record · CVE-2025-30676 · published 1 April 2025

CVE-2025-30676: Apache OFBiz reflected XSS in web page output

Apache · Ofbiz

Apache OFBiz before 18.12.19 fails to neutralize script-related HTML tags, allowing basic reflected cross-site scripting. Because OFBiz is a widely deployed business application platform, a successful attack can run script in a victim's browser session in the context of the application.

6.1 CVSS 3.1 Medium EPSS 68% · top 0.7% CWE-80 · CWE-80CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS 6.1 medium severity with required user interaction, but high EPSS and a widely used product raise the practical risk.

What it is

Apache OFBiz before 18.12.19 fails to neutralize script-related HTML tags, allowing basic reflected cross-site scripting. Because OFBiz is a widely deployed business application platform, a successful attack can run script in a victim's browser session in the context of the application.

Impact

An attacker can execute arbitrary JavaScript in a victim's browser, potentially stealing session cookies, reading page content, or performing actions as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network with no authentication (PR:N), but exploitation requires the victim to interact with a crafted link or page (UI:R). The CVSS vector confirms network vector, low complexity, and user interaction.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.676 (99.3rd percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Upgrade Apache OFBiz to 18.12.19 or later, which fixes the issue.
  • If immediate upgrade is not possible, apply input validation and output encoding for script-related HTML tags on affected endpoints.
  • Deploy a web application firewall rule set to block common XSS payloads targeting OFBiz.
  • Restrict network exposure of OFBiz instances to trusted users where feasible.
  • Monitor vendor advisory and Jira OFBIZ-13219 for patch details and backports.

Detection

  • Inspect web server and application logs for requests containing script tags or event handler attributes in parameters.
  • Monitor for anomalous JavaScript execution or outbound requests from user browsers following OFBiz page loads.
  • Review WAF alerts for XSS patterns against OFBiz endpoints.
  • Correlate suspicious session activity or cookie theft indicators with OFBiz access logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30676 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2025-30676), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.