CVE-2025-30676

CVE-2025-30676: Apache OFBiz: Stored XSS Vulnerability

Vendor Apache Software Foundation
Product Apache OFBiz
Weakness CWE-80 · XSS · basic
Published April 1, 2025
Last update April 2, 2025

CVSS base score

What the vulnerability does

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

Key dates

Disclosure timeline

April 1, 2025 CVE published
April 2, 2025 Record updated